SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityAnalyzed

CVE-2020-35730

Roundcube Webmail Cross-Site Scripting (XSS) Vulnerability

KEVMEDIUM 6.1EPSS 32.7%

Does this matter?

Known to be exploited in the wild (CISA KEV, CISA remediation deadline 13 July 2023). Treat as an emergency change: patch or isolate now, then hunt for prior compromise.

Description

An XSS issue was discovered in Roundcube Webmail before 1.2.13, 1.3.x before 1.3.16, and 1.4.x before 1.4.10. The attacker can send a plain text e-mail message, with JavaScript in a link reference element that is mishandled by linkref_addindex in rcube_string_replacer.php.

CVSS 3.1
6.1 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
EPSS
32.69% probability · 98th percentile
CISA KEV
Listed 22 June 2023 · due 13 July 2023
Weakness
CWE-79
Affected
roundcube/webmail · fedoraproject/fedora · debian/debian linux
Source
cve@mitre.org

CISA notes

Apply updates per vendor instructions. https://roundcube.net/news/2020/12/27/security-updates-1.4.10-1.3.16-and-1.2.13; https://nvd.nist.gov/vuln/detail/CVE-2020-35730

References

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.