Description
An issue was discovered in Roundcube Webmail before 1.2.11, 1.3.x before 1.3.14, and 1.4.x before 1.4.7. It allows XSS via a crafted HTML e-mail message, as demonstrated by a JavaScript payload in the xmlns (aka XML namespace) attribute of a HEAD element when an SVG element exists.
Remediation
References
Related Vulnerabilities
PHP Other Vulnerability (CVE-2015-6837)
Apache Tomcat Permissions, Privileges, and Access Controls Vulnerability (CVE-2014-0119)
WordPress Plugin Backup Migration Information Disclosure (1.2.8)
WordPress Plugin Colorful Categories Cross-Site Request Forgery (2.0.14)
phpMyAdmin 7PK - Security Features Vulnerability (CVE-2016-6629)