CVE-2020-13965

CVE Published 2020-06-09
Related CWE(s) CWE-80: Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS), CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Related Vendor(s) fedoraproject, roundcube, debian
Related Product(s) fedora, webmail, debian_linux
Exploitation Reported (CISA KEV) 2024-06-26
CVSS 3 Base Score 6.3 (MEDIUM)
CVSS 3 Attack Complexity LOW
CVSS 3 Attack Vector NETWORK

An issue was discovered in Roundcube Webmail before 1.3.12 and 1.4.x before 1.4.5. There is XSS via a malicious XML attachment because text/xml is among the allowed types for a preview.

Cyber Threat Graph Context

Explore how this CVE relates to the wider threat graph

Associated CAPEC Patterns

References