CVE-2020-16145: XSS
Published Aug 12, 2020
·Updated
Roundcube Webmail before 1.3.15 and 1.4.8 allows stored XSS in HTML messages during message display via a crafted SVG document. This issue has been fixed in 1.4.8 and 1.3.15.
Affected Software
4 affected components
Roundcube Webmail<1.3.15
Roundcube Webmail>=1.4.0<1.4.8
Fedoraproject Fedora=31
Fedoraproject Fedora=32
Remediation
Event History
Aug 12, 2020
CVE Published
via MITRE·12:29 PM
Data Sourced
via MITRE·12:29 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID of this issue?
The vulnerability ID of this issue is CVE-2020-16145.
2
What is the severity of CVE-2020-16145?
CVE-2020-16145 has a severity value of 6.1, which is considered medium.
3
How does CVE-2020-16145 impact Roundcube Webmail?
CVE-2020-16145 allows stored cross-site scripting (XSS) attacks in HTML messages displayed in Roundcube Webmail.
4
Which versions of Roundcube Webmail are affected by CVE-2020-16145?
Roundcube Webmail versions up to and including 1.3.15 and versions from 1.4.0 up to and including 1.4.8 are affected.
5
How can I fix CVE-2020-16145?
CVE-2020-16145 has been fixed in Roundcube Webmail version 1.4.8 and 1.3.15. It is recommended to upgrade to these versions.