Description
An issue was discovered in Roundcube Webmail before 1.4.4. There is a cross-site scripting (XSS) vulnerability in rcube_washtml.php because JavaScript code can occur in the CDATA of an HTML message.
Remediation
References
Related Vulnerabilities
Oracle HTTP Server CVE-2007-0280 Vulnerability (CVE-2007-0280)
Magento Incorrect Authorization Vulnerability (CVE-2020-9587)
PHP Integer Overflow or Wraparound Vulnerability (CVE-2018-14883)
PHP Other Vulnerability (CVE-2005-3319)
WordPress Plugin Plugin Central Multiple Cross-Site Scripting Vulnerabilities (2.5)