CVE-2021-26925: XSS
Published Feb 9, 2021
·Updated
Roundcube before 1.4.11 allows XSS via crafted Cascading Style Sheets (CSS) token sequences during HTML email rendering.
Affected Software
3 affected components
Roundcube Webmail<1.4.11
Fedoraproject Fedora=32
Fedoraproject Fedora=33
Remediation
Event History
Feb 9, 2021
CVE Published
via MITRE·08:53 AM
Data Sourced
via MITRE·08:53 AM
Description
Frequently Asked Questions
1
What is CVE-2021-26925?
CVE-2021-26925 is a vulnerability in Roundcube Webmail before version 1.4.11 that allows cross-site scripting (XSS) via crafted Cascading Style Sheets (CSS) token sequences during HTML email rendering.
2
How does CVE-2021-26925 impact Roundcube Webmail?
CVE-2021-26925 allows an attacker to execute malicious scripts in the victim's browser when they view a specially crafted email in Roundcube Webmail.
3
What is the severity of CVE-2021-26925?
CVE-2021-26925 has a severity rating of medium with a CVSS score of 5.4.
4
Which versions of Roundcube Webmail are affected by CVE-2021-26925?
Roundcube Webmail versions prior to 1.4.11 are affected by CVE-2021-26925.
5
How can I mitigate the vulnerability CVE-2021-26925?
To mitigate CVE-2021-26925, it is recommended to update Roundcube Webmail to version 1.4.11 or later.