CVE-2020-15562: XSS
An issue was discovered in Roundcube Webmail before 1.2.11, 1.3.x before 1.3.14, and 1.4.x before 1.4.7. It allows XSS via a crafted HTML e-mail message, as demonstrated by a JavaScript payload in the xmlns (aka XML namespace) attribute of a HEAD element when an SVG element exists.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the vulnerability ID for this issue in Roundcube Webmail?
The vulnerability ID for this issue in Roundcube Webmail is CVE-2020-15562.
What is the severity of CVE-2020-15562?
The severity of CVE-2020-15562 is high with a severity value of 6.1.
How does CVE-2020-15562 impact Roundcube Webmail?
CVE-2020-15562 allows XSS (cross-site scripting) attacks via a crafted HTML e-mail message in Roundcube Webmail.
Which versions of Roundcube Webmail are affected by CVE-2020-15562?
Roundcube Webmail versions before 1.2.11, 1.3.x before 1.3.14, and 1.4.x before 1.4.7 are affected by CVE-2020-15562.
How can I fix CVE-2020-15562 in Roundcube Webmail?
To fix CVE-2020-15562 in Roundcube Webmail, update to version 1.2.11, 1.3.14, or 1.4.7 or later.