CVE-2023-5631: Stored XSS vulnerability in Roundcube
Last updated 21 August 2024
Other sources
Roundcube before 1.4.15, 1.5.x before 1.5.5, and 1.6.x before 1.6.4 allows stored XSS via an HTML e-mail message with a crafted SVG document because of program/lib/Roundcube/rcubewashtml.php behavior. This could allow a remote attacker
to load arbitrary JavaScript code.
Roundcube Webmail contains a persistent cross-site scripting (XSS) vulnerability that allows a remote attacker to run malicious JavaScript code.
— CISA
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/roundcubeto a version that resolves this vulnerability.Fixed in 1.6.4+dfsg-1Fixed in 1.6.4+dfsg-1~deb12u1Fixed in 1.4.15+dfsg.1-1~deb11u1 - Upgrade
Upgrade
debian/roundcubeto a version that resolves this vulnerability.Fixed in 1.4.15+dfsg.1-1+deb11u4Fixed in 1.4.15+dfsg.1-1+deb11u6Fixed in 1.6.5+dfsg-1+deb12u6Fixed in 1.6.12+dfsg-0+deb13u1Fixed in 1.6.12+dfsg-1 - Upgrade
Upgrade
debian/roundcubeto a version that resolves this vulnerability.Fixed in 1.4.15+dfsg.1-1+deb11u4 - Upgrade
Upgrade
debian/roundcubeto a version that resolves this vulnerability.Fixed in 1.4.15+dfsg.1-1+deb11u6 - Upgrade
Upgrade
debian/roundcubeto a version that resolves this vulnerability.Fixed in 1.6.5+dfsg-1+deb12u6 - Upgrade
Upgrade
debian/roundcubeto a version that resolves this vulnerability.Fixed in 1.6.12+dfsg-0+deb13u1 - Upgrade
Upgrade
debian/roundcubeto a version that resolves this vulnerability.Fixed in 1.6.12+dfsg-1 - Upgrade
Upgrade
debian/roundcubeto a version that resolves this vulnerability.Fixed in 1.6.4+dfsg-1 - Upgrade
Upgrade
debian/roundcubeto a version that resolves this vulnerability.Fixed in 1.6.4+dfsg-1~deb12u1 - Upgrade
Upgrade
debian/roundcubeto a version that resolves this vulnerability.Fixed in 1.4.15+dfsg.1-1~deb11u1 - Upgrade
Upgrade
Roundcubeto a version that resolves this vulnerability.Fixed in 1.4.15 - Upgrade
Upgrade
Roundcubeto a version that resolves this vulnerability.Fixed in 1.5.5 - Upgrade
Upgrade
Roundcubeto a version that resolves this vulnerability.Fixed in 1.6.4 - Compensating control
Discontinue use of the product if mitigations are unavailable.
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the vulnerability ID for this Roundcube vulnerability?
The vulnerability ID for this Roundcube vulnerability is CVE-2023-5631.
What is the severity of CVE-2023-5631?
The severity of CVE-2023-5631 is high with a severity value of 6.1.
How does CVE-2023-5631 allow stored XSS?
CVE-2023-5631 allows stored XSS through an HTML e-mail message with a crafted SVG document because of program/lib/Roundcube/rcube_washtml.php behavior.
Which versions of Roundcube are affected by CVE-2023-5631?
Roundcube versions before 1.4.15, 1.5.x before 1.5.5, and 1.6.x before 1.6.4 are affected by CVE-2023-5631.
How can I fix CVE-2023-5631?
To fix CVE-2023-5631, upgrade to Roundcube version 1.4.15, 1.5.5, or 1.6.4.