CVE-2023-43770

CVE Published 2023-09-22
Related CWE(s) CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Related Vendor(s) roundcube, debian
Related Product(s) webmail, debian_linux
Exploitation Reported (CISA KEV) 2024-02-12
CVSS 3 Base Score 6.1 (MEDIUM)
CVSS 3 Attack Complexity LOW
CVSS 3 Attack Vector NETWORK

Roundcube before 1.4.14, 1.5.x before 1.5.4, and 1.6.x before 1.6.3 allows XSS via text/plain e-mail messages with crafted links because of program/lib/Roundcube/rcube_string_replacer.php behavior.

Cyber Threat Graph Context

Explore how this CVE relates to the wider threat graph

Associated CAPEC Patterns

References