Loading HuntDB...

GHSA-qf8f-27cp-gw76

GitHub Security Advisory

⚠ Unreviewed MODERATE Has CVE

Advisory Details


Roundcube before 1.4.15, 1.5.x before 1.5.5, and 1.6.x before 1.6.4 allows stored XSS via an HTML e-mail message with a crafted SVG document because of program/lib/Roundcube/rcube_washtml.php behavior. This could allow a remote attacker

to load arbitrary JavaScript code.

Related CVEs

Key Information

GHSA ID
GHSA-qf8f-27cp-gw76
Published
October 18, 2023 3:30 PM
Last Modified
January 28, 2025 12:32 AM
CVSS Score
5.0 /10
Primary Ecosystem
Unknown
Primary Package
Unknown
GitHub Reviewed
✗ No

Dataset

Last updated: June 15, 2025 6:24 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.