Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Vulnerabilities CVE-2020-35730

CVE-2020-35730

Medium
Open
KEV
TLP:CLEAR

Roundcube Webmail Cross-Site Scripting (XSS) Vulnerability

AI Analysis

No AI analysis yet.

Description

Roundcube — Roundcube Webmail — Roundcube Webmail contains a cross-site scripting (XSS) vulnerability that allows an attacker to send a plain text e-mail message with Javascript in a link reference element that is mishandled by linkref_addinindex in rcube_string_replacer.php.

Details

EPSS Score
32.69%

98.2th percentile

Confidence
100%
CISA KEV
Date Added
Jun 22, 2023
Patch Due
Jul 13, 2023
Required Action
Apply updates per vendor instructions.
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.