Loading HuntDB...

Roundcube Webmail Persistent Cross-Site Scripting (XSS) Vulnerability

Added Feb. 12, 2024 Due March 4, 2024 CVE-2023-43770
Overdue Roundcube / Webmail CWE-79

Description

Roundcube Webmail contains a persistent cross-site scripting (XSS) vulnerability that can lead to information disclosure via malicious link references in plain/text messages.

Required Action

Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

References

Additional Information

Catalog Version
2025.01.24
Catalog Released
Jan. 24, 2025
Days Until Due
0 days
Last Updated
4 months, 2 weeks ago