CVE-2020-12625
04.05.2020, 02:15
An issue was discovered in Roundcube Webmail before 1.4.4. There is a cross-site scripting (XSS) vulnerability in rcube_washtml.php because JavaScript code can occur in the CDATA of an HTML message.
| Vendor | Product | Version |
|---|---|---|
| roundcube | webmail | 𝑥 < 1.4.4 |
| debian | debian_linux | 9.0 |
| debian | debian_linux | 10.0 |
| opensuse | backports_sle | 15.0:sp1 |
| opensuse | backports_sle | 15.0:sp2 |
| opensuse | leap | 15.1 |
| opensuse | leap | 15.2 |
𝑥
= Vulnerable software versions
Debian Releases
Ubuntu Releases
Ubuntu Product | |||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| roundcube |
|
References