Roundcube before 1.4.15, 1.5.x before 1.5.5, and 1.6.x before 1.6.4 allows stored XSS via an HTML e-mail message with a crafted SVG document because of program/lib/Roundcube/rcube_washtml.php behavior. This could allow a remote attacker to load arbitrary JavaScript code.
Roundcube before 1.4.15, 1.5.x before 1.5.5, and 1.6.x before 1.6.4 allows stored XSS via an HTML e-mail message with a crafted SVG document because of program/lib/Roundcube/rcube_washtml.php behavior. This could allow a remote attacker
to load arbitrary JavaScript code.
Why this VPI (explainable, experimental)
VPI breakdown
| Impact | 61.00 |
| Exploitation signal(KEV listed) | ×1.50 |
| VPI | 91.50 |
VPI formula vpi-v1
Required Action
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.