Roundcube — Webmail — Roundcube Webmail contains a persistent cross-site scripting (XSS) vulnerability that allows a remote attacker to run malicious JavaScript code.
Details
EPSS Score
ⓘ
75.87%
99.5th percentile
Confidence
100%
CISA KEV
Date Added
Oct 26, 2023
Patch Due
Nov 16, 2023
Required Action
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.