Vulnerability Description
An XSS issue was discovered in Roundcube Webmail before 1.2.13, 1.3.x before 1.3.16, and 1.4.x before 1.4.10. The attacker can send a plain text e-mail message, with JavaScript in a link reference element that is mishandled by linkref_addindex in rcube_string_replacer.php.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Roundcube | Webmail | < 1.2.13 |
| Fedoraproject | Fedora | 32 |
| Debian | Debian Linux | 9.0 |
Related Weaknesses (CWE)
References
- https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=978491Issue TrackingMailing List
- https://github.com/roundcube/roundcubemail/compare/1.4.9...1.4.10Patch
- https://github.com/roundcube/roundcubemail/releases/tag/1.2.13Release Notes
- https://github.com/roundcube/roundcubemail/releases/tag/1.3.16Release Notes
- https://github.com/roundcube/roundcubemail/releases/tag/1.4.10Release Notes
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproMailing ListRelease Notes
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproMailing ListRelease Notes
- https://roundcube.net/download/Product
- https://www.alexbirnberg.com/roundcube-xss.htmlBroken Link
- https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=978491Issue TrackingMailing List
- https://github.com/roundcube/roundcubemail/compare/1.4.9...1.4.10Patch
- https://github.com/roundcube/roundcubemail/releases/tag/1.2.13Release Notes
- https://github.com/roundcube/roundcubemail/releases/tag/1.3.16Release Notes
- https://github.com/roundcube/roundcubemail/releases/tag/1.4.10Release Notes
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproMailing ListRelease Notes
FAQ
What is CVE-2020-35730?
CVE-2020-35730 is a vulnerability with a CVSS score of 6.1 (MEDIUM). An XSS issue was discovered in Roundcube Webmail before 1.2.13, 1.3.x before 1.3.16, and 1.4.x before 1.4.10. The attacker can send a plain text e-mail message, with JavaScript in a link reference ele...
How severe is CVE-2020-35730?
CVE-2020-35730 has been rated MEDIUM with a CVSS base score of 6.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2020-35730?
Check the references section above for vendor advisories and patch information. Affected products include: Roundcube Webmail, Fedoraproject Fedora, Debian Debian Linux.