CVE-2023-47272
06.11.2023, 00:15
Roundcube 1.5.x before 1.5.6 and 1.6.x before 1.6.5 allows XSS via a Content-Type or Content-Disposition header (used for attachment preview or download).
Vendor | Product | Version |
---|---|---|
roundcube | webmail | 1.5.0 ≤ 𝑥 < 1.5.6 |
roundcube | webmail | 1.6.0 ≤ 𝑥 < 1.6.5 |
debian | debian_linux | 10.0 |
debian | debian_linux | 11.0 |
debian | debian_linux | 12.0 |
𝑥
= Vulnerable software versions

Debian Releases

Ubuntu Releases
References