SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityAnalyzed

CVE-2023-5631

Roundcube Webmail Persistent Cross-Site Scripting (XSS) Vulnerability

KEVMEDIUM 5.4EPSS 75.9%

Does this matter?

Known to be exploited in the wild (CISA KEV, CISA remediation deadline 16 November 2023). Treat as an emergency change: patch or isolate now, then hunt for prior compromise.

Description

Roundcube before 1.4.15, 1.5.x before 1.5.5, and 1.6.x before 1.6.4 allows stored XSS via an HTML e-mail message with a crafted SVG document because of program/lib/Roundcube/rcube_washtml.php behavior. This could allow a remote attacker to load arbitrary JavaScript code.

CVSS 3.1
5.4 MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
EPSS
75.87% probability · 99th percentile
CISA KEV
Listed 26 October 2023 · due 16 November 2023
Weakness
CWE-79
Affected
roundcube/webmail · debian/debian linux · fedoraproject/fedora
Source
security@eset.com

CISA notes

Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. https://roundcube.net/news/2023/10/16/security-update-1.6.4-released, https://roundcube.net/news/2023/10/16/security-updates-1.5.5-and-1.4.15 ; https://nvd.nist.gov/vuln/detail/CVE-2023-5631

References

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.