Description
Roundcube Webmail before 1.3.15 and 1.4.8 allows stored XSS in HTML messages during message display via a crafted SVG document. This issue has been fixed in 1.4.8 and 1.3.15.
Remediation
References
Related Vulnerabilities
Drupal URL Redirection to Untrusted Site ('Open Redirect') Vulnerability (CVE-2015-2750)
WordPress Plugin qTranslate X Multiple Cross-Site Scripting Vulnerabilities (3.4.6.8)
Jenkins Integer Overflow or Wraparound Vulnerability (CVE-2023-36478)
Artifactory Exposure of Resource to Wrong Sphere Vulnerability (CVE-2021-46687)
WordPress Plugin EWWW Image Optimizer Cloud Cross-Site Scripting (2.0.1)