CVE-2020-18671: XSS
Published Jun 24, 2021
·Updated
Cross Site Scripting (XSS) vulnerability in Roundcube Mail <=1.4.4 via smtp config in /installer/test.php.
Affected Software
1 affected component
Roundcube Webmail<=1.4.4
Remediation
Patch Available
Event History
Jun 24, 2021
CVE Published
via MITRE·06:14 PM
Data Sourced
via MITRE·06:14 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID?
The vulnerability ID is CVE-2020-18671.
2
What is the title of the vulnerability?
The title of the vulnerability is Cross Site Scripting (XSS) vulnerability in Roundcube Mail <=1.4.4 via smtp config in /installer/test.php.
3
What is the severity of CVE-2020-18671?
The severity of CVE-2020-18671 is medium with a severity value of 5.4.
4
Which software versions are affected by this vulnerability?
The vulnerability affects Roundcube Mail version up to and inclusive of 1.4.4.
5
How can I fix this vulnerability?
To fix this vulnerability, update Roundcube Mail to version 1.4.5 or 1.3.12.