CVE-2020-35730

MEDIUM WAF: High
CVSS 6.1 Published: 2020-12-28
CWE-79 CWE-79

An XSS issue was discovered in Roundcube Webmail before 1.2.13, 1.3.x before 1.3.16, and 1.4.x before 1.4.10. The attacker can send a plain text e-mail message, with JavaScript in a link reference element that is mishandled by linkref_addindex in rcube_string_replacer.php.

WAF Coverage Analysis

Cross-Site Scripting (XSS) High WAF Coverage

OWASP: A03:2021 Injection

941xxx - XSS / XXE
Cross-Site Scripting (XSS) High WAF Coverage

OWASP: A03:2021 Injection

941xxx - XSS / XXE

Affected Software

VendorProductVersion
roundcubewebmailup to 1.2.13
roundcubewebmail1.3.0 - 1.3.16
roundcubewebmail1.4 - 1.4.10
fedoraprojectfedora32
fedoraprojectfedora33
debiandebian_linux9.0

References

Back to CVE Database