CVE-2020-35730

CVE Published 2020-12-28
Related CWE(s) CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Related Vendor(s) fedoraproject, roundcube, debian
Related Product(s) fedora, webmail, debian_linux
Exploitation Reported (CISA KEV) 2023-06-22
CVSS 3 Base Score 6.1 (MEDIUM)
CVSS 3 Attack Complexity LOW
CVSS 3 Attack Vector NETWORK

An XSS issue was discovered in Roundcube Webmail before 1.2.13, 1.3.x before 1.3.16, and 1.4.x before 1.4.10. The attacker can send a plain text e-mail message, with JavaScript in a link reference element that is mishandled by linkref_addindex in rcube_string_replacer.php.

Cyber Threat Graph Context

Explore how this CVE relates to the wider threat graph

Associated CAPEC Patterns

References