CVE-2020-18670: XSS
Published Jun 24, 2021
·Updated
Cross Site Scripting (XSS) vulneraibility in Roundcube mail .4.4 via database host and user in /installer/test.php.
Affected Software
1 affected component
Roundcube Webmail=1.4.4
Remediation
Patch Available
Event History
Jun 24, 2021
CVE Published
via MITRE·06:07 PM
Data Sourced
via MITRE·06:07 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID for this XSS vulnerability?
The vulnerability ID for this Cross Site Scripting (XSS) vulnerability is CVE-2020-18670.
2
What is the severity of CVE-2020-18670?
The severity of CVE-2020-18670 is medium with a severity value of 5.4.
3
Which software is affected by CVE-2020-18670?
Roundcube Webmail version 1.4.4 is affected by CVE-2020-18670.
4
How can I exploit CVE-2020-18670?
We do not provide information or support for exploiting vulnerabilities.
5
How can I fix CVE-2020-18670?
Update Roundcube Webmail to version 1.4.5 or 1.3.12 as recommended by the Roundcube project.