CVE-2020-35730: Roundcube Webmail Cross-Site Scripting (XSS) Vulnerability
An XSS issue was discovered in Roundcube Webmail before 1.2.13, 1.3.x before 1.3.16, and 1.4.x before 1.4.10. The attacker can send a plain text e-mail message, with JavaScript in a link reference element that is mishandled by linkrefaddindex in rcubestringreplacer.php.
Other sources
Roundcube Webmail contains a cross-site scripting (XSS) vulnerability that allows an attacker to send a plain text e-mail message with Javascript in a link reference element that is mishandled by linkrefaddinindex in rcubestringreplacer.php.
— CISA
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/roundcubeto a version that resolves this vulnerability.Fixed in 1.4.10+dfsg.1-1Fixed in 1.3.16+dfsg.1-1~deb10u1 - Upgrade
Upgrade
debian/roundcubeto a version that resolves this vulnerability.Fixed in 1.4.15+dfsg.1-1+deb11u4Fixed in 1.4.15+dfsg.1-1+deb11u6Fixed in 1.6.5+dfsg-1+deb12u6Fixed in 1.6.12+dfsg-0+deb13u1Fixed in 1.6.12+dfsg-1
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the vulnerability ID for the Roundcube Webmail cross-site scripting (XSS) vulnerability?
The vulnerability ID for the Roundcube Webmail cross-site scripting (XSS) vulnerability is CVE-2020-35730.
What is the description of CVE-2020-35730?
CVE-2020-35730 is a cross-site scripting (XSS) vulnerability in Roundcube Webmail that allows an attacker to send a plain text e-mail message with JavaScript in a link reference element.
What software is affected by CVE-2020-35730?
Roundcube Webmail versions are affected by the CVE-2020-35730 vulnerability.
How can an attacker exploit CVE-2020-35730?
An attacker can exploit CVE-2020-35730 by sending a plain text e-mail message with JavaScript in a malformed link reference element.
Where can I find more information about CVE-2020-35730?
You can find more information about CVE-2020-35730 on the Roundcube Webmail website.