CVE-2024-37383: RoundCube Webmail Cross-Site Scripting (XSS) Vulnerability
Last updated 24 July 2024
Other sources
Roundcube Webmail before 1.5.7 and 1.6.x before 1.6.7 allows XSS via SVG animate attributes.
— Launchpad
RoundCube Webmail contains a cross-site scripting (XSS) vulnerability in the handling of SVG animate attributes that allows a remote attacker to run malicious JavaScript code.
— CISA
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/roundcubeto a version that resolves this vulnerability.Fixed in 1.4.15+dfsg.1-1+deb11u4Fixed in 1.6.5+dfsg-1+deb12u4Fixed in 1.6.9+dfsg-1 - Upgrade
Upgrade
debian/roundcubeto a version that resolves this vulnerability.Fixed in 1.4.15+dfsg.1-1+deb11u4 - Upgrade
Upgrade
debian/roundcubeto a version that resolves this vulnerability.Fixed in 1.6.5+dfsg-1+deb12u4 - Upgrade
Upgrade
debian/roundcubeto a version that resolves this vulnerability.Fixed in 1.6.9+dfsg-1 - Upgrade
Upgrade
Roundcube Webmailto a version that resolves this vulnerability.Fixed in 1.5.7 - Upgrade
Upgrade
Roundcube Webmailto a version that resolves this vulnerability.Fixed in 1.6.7
Event History
Frequently Asked Questions
What is the severity of CVE-2024-37383?
CVE-2024-37383 is classified as a moderate severity cross-site scripting (XSS) vulnerability.
How do I fix CVE-2024-37383?
To fix CVE-2024-37383, update Roundcube Webmail to version 1.5.7 or 1.6.7 or later.
What software is affected by CVE-2024-37383?
CVE-2024-37383 affects Roundcube Webmail versions prior to 1.5.7 and versions between 1.6.0 and 1.6.6.
Can CVE-2024-37383 be exploited remotely?
Yes, a remote attacker can exploit CVE-2024-37383 to execute malicious JavaScript through XSS.
What are the potential impacts of CVE-2024-37383?
Exploitation of CVE-2024-37383 can lead to unauthorized access to sensitive information and user session hijacking.