CVE-2023-5631

medium

Description

Roundcube before 1.4.15, 1.5.x before 1.5.5, and 1.6.x before 1.6.4 allows stored XSS via an HTML e-mail message with a crafted SVG document because of program/lib/Roundcube/rcube_washtml.php behavior. This could allow a remote attacker to load arbitrary JavaScript code.

References

https://web-assets.esetstatic.com/wls/en/papers/threat-reports/eset-apt-activity-report-q4-2023-q1-2024.pdf

https://www.securityweek.com/russian-cyberspies-exploit-roundcube-flaws-against-european-governments/

https://thecyberthrone.in/2024/02/13/cisa-adds-roundcube-webmail-cve-2023-43770-to-its-kev-catalog/

https://www.bleepingcomputer.com/news/security/cisa-roundcube-email-server-bug-now-exploited-in-attacks/

https://thehackernews.com/2023/10/nation-state-hackers-exploiting-zero.html

https://www.debian.org/security/2023/dsa-5531

https://roundcube.net/news/2023/10/16/security-updates-1.5.5-and-1.4.15

https://roundcube.net/news/2023/10/16/security-update-1.6.4-released

https://lists.fedoraproject.org/archives/list/[email protected]/message/LK67Q46OIEGJCRQUBHKLH3IIJTBNGGX4/

https://lists.debian.org/debian-lts-announce/2023/10/msg00035.html

https://github.com/roundcube/roundcubemail/releases/tag/1.6.4

https://github.com/roundcube/roundcubemail/releases/tag/1.5.5

https://github.com/roundcube/roundcubemail/releases/tag/1.4.15

https://github.com/roundcube/roundcubemail/commit/6ee6e7ae301e165e2b2cb703edf75552e5376613

https://github.com/roundcube/roundcubemail/commit/41756cc3331b495cc0b71886984474dc529dd31d

https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1054079

http://www.openwall.com/lists/oss-security/2023/11/17/2

http://www.openwall.com/lists/oss-security/2023/11/01/3

http://www.openwall.com/lists/oss-security/2023/11/01/1

Details

Source: Mitre, NVD

Published: 2023-10-18

Updated: 2023-12-22

Risk Information

CVSS v2

Base Score: 5.5

Vector: CVSS2#AV:N/AC:L/Au:S/C:P/I:P/A:N

Severity: Medium

CVSS v3

Base Score: 5.4

Vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

Severity: Medium