← Voltar para CVEs
CVE-2020-35730
MEDIUMCISA KEV6.1
Descricao
An XSS issue was discovered in Roundcube Webmail before 1.2.13, 1.3.x before 1.3.16, and 1.4.x before 1.4.10. The attacker can send a plain text e-mail message, with JavaScript in a link reference element that is mishandled by linkref_addindex in rcube_string_replacer.php.
Detalhes CVE
Pontuacao CVSS v3.16.1
SeveridadeMEDIUM
Vetor CVSSCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Vetor de ataqueNETWORK
ComplexidadeLOW
Privilegios necessariosNONE
Interacao do usuarioREQUIRED
Publicado12/28/2020
Ultima modificacao11/4/2025
Fontekev
Avistamentos honeypot0
CISA KEV
FornecedorRoundcube
ProdutoRoundcube Webmail
Nome da vulnerabilidadeRoundcube Webmail Cross-Site Scripting (XSS) Vulnerability
Data inclusao KEV2023-06-22
Prazo de remediacao2023-07-13
Uso em ransomwareUnknown
Produtos afetados
debian:debian_linuxfedoraproject:fedoraroundcube:webmail
Fraquezas (CWE)
CWE-79CWE-79
Referencias
https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=978491(cve@mitre.org)
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/HCEU4BM5WGIDJWP6Z4PCH62ZMH57QYM2/(cve@mitre.org)
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/HMLIZWKMTRCLU7KZLEQHELS4INXJ7X5Q/(cve@mitre.org)
https://roundcube.net/download/(cve@mitre.org)
https://www.alexbirnberg.com/roundcube-xss.html(cve@mitre.org)
https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=978491(af854a3a-2127-422b-91ae-364da2661108)
https://github.com/roundcube/roundcubemail/compare/1.4.9...1.4.10(af854a3a-2127-422b-91ae-364da2661108)
https://github.com/roundcube/roundcubemail/releases/tag/1.2.13(af854a3a-2127-422b-91ae-364da2661108)
https://github.com/roundcube/roundcubemail/releases/tag/1.3.16(af854a3a-2127-422b-91ae-364da2661108)
https://github.com/roundcube/roundcubemail/releases/tag/1.4.10(af854a3a-2127-422b-91ae-364da2661108)
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/HCEU4BM5WGIDJWP6Z4PCH62ZMH57QYM2/(af854a3a-2127-422b-91ae-364da2661108)
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/HMLIZWKMTRCLU7KZLEQHELS4INXJ7X5Q/(af854a3a-2127-422b-91ae-364da2661108)
https://roundcube.net/download/(af854a3a-2127-422b-91ae-364da2661108)
https://www.alexbirnberg.com/roundcube-xss.html(af854a3a-2127-422b-91ae-364da2661108)
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2020-35730(134c704f-9b21-4f2e-91b3-4a467353bcc0)
Correlacoes IOC
Sem correlacoes registradas
This product uses data from the NVD API but is not endorsed or certified by the NVD.