CVE-2023-47272: XSS
Published Nov 5, 2023
·Updated
Last updated 24 July 2024
Other sources
Roundcube 1.5.x before 1.5.6 and 1.6.x before 1.6.5 allows XSS via a Content-Type or Content-Disposition header (used for attachment preview or download).
— NVD
Affected Software
10 affected componentsFixes available
debian/roundcube<=1.6.4+dfsg-1, <=1.6.4+dfsg-1~deb12u1, <=1.4.15+dfsg.1-1~deb11u1
1.6.5+dfsg-11.6.5+dfsg-1~deb12u11.4.15+dfsg.1-1~deb11u2
debian/roundcube
1.4.15+dfsg.1-1+deb11u41.6.5+dfsg-1+deb12u41.6.9+dfsg-1
Roundcube Webmail>=1.5.0<1.5.6
Roundcube Webmail>=1.6.0<1.6.5
Fedoraproject Fedora=37
Fedoraproject Fedora=38
Fedoraproject Fedora=39
Debian Debian Linux=10.0
Debian Debian Linux=11.0
Debian Debian Linux=12.0
Remediation
Event History
Nov 5, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionSeverity
Nov 6, 2023
Data Sourced
via NVD·12:15 AM
RemedyDescriptionSeverityWeaknessAffected Software
Jun 26, 2024
Data Sourced
via Launchpad·09:46 AM
Description
Sep 14, 2024
Data Sourced
via Ubuntu·10:00 AM
RemedyDescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the vulnerability ID?
The vulnerability ID is CVE-2023-47272.
2
What is the title of the vulnerability?
The title of the vulnerability is Roundcube 1.5.x before 1.5.6 and 1.6.x before 1.6.5 allows XSS via a Content-Type or Content-Disposition header.
3
What is the severity of CVE-2023-47272?
The severity of CVE-2023-47272 is medium with a severity value of 6.1.
4
What software is affected by CVE-2023-47272?
Roundcube Webmail versions 1.5.x before 1.5.6 and 1.6.x before 1.6.5 are affected by CVE-2023-47272.
5
How can I fix CVE-2023-47272?
To fix CVE-2023-47272, it is recommended to update to Roundcube Webmail versions 1.5.6 or 1.6.5.