CVE-2021-46144
EUVD-2021-3284406.01.2022, 05:15
Roundcube before 1.4.13 and 1.5.x before 1.5.2 allows XSS via an HTML e-mail message with crafted Cascading Style Sheets (CSS) token sequences.
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| roundcube | roundcube | 𝑥 < 1.4.13 |
| roundcube | roundcube | 1.5.0 ≤ 𝑥 < 1.5.2 |
| debian | debian_linux | 9.0 |
| debian | debian_linux | 10.0 |
| debian | debian_linux | 11.0 |
𝑥
= Vulnerable software versions
Debian Releases
Ubuntu Releases
References