Description
Cross-site scripting (XSS) vulnerability in program/include/rcmail.php in Roundcube Webmail 1.1.x before 1.1.2 allows remote attackers to inject arbitrary web script or HTML via the _mbox parameter to the default URI.
Remediation
References
Related Vulnerabilities
WordPress Plugin Login Security Solution Multiple Unspecified Vulnerabilities (0.50.0)
Oracle JRE CVE-2012-4681 Vulnerability (CVE-2012-4681)
Oracle Application Server CVE-2006-0289 Vulnerability (CVE-2006-0289)
phpMyAdmin Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2018-10188)
Joomla Generation of Error Message Containing Sensitive Information Vulnerability (CVE-2018-11325)