Roundcube — Webmail — Roundcube Webmail contains a persistent cross-site scripting (XSS) vulnerability that can lead to information disclosure via malicious link references in plain/text messages.
Details
EPSS Score
ⓘ
58.48%
99th percentile
Confidence
100%
CISA KEV
Date Added
Feb 12, 2024
Patch Due
Mar 4, 2024
Required Action
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.