Description
An XSS issue was discovered in Roundcube Webmail before 1.2.13, 1.3.x before 1.3.16, and 1.4.x before 1.4.10. The attacker can send a plain text e-mail message, with JavaScript in a link reference element that is mishandled by linkref_addindex in rcube_string_replacer.php.
Remediation
References
Related Vulnerabilities
WebLogic CVE-2024-21182 Vulnerability (CVE-2024-21182)
Drupal CVE-2022-25278 Vulnerability (CVE-2022-25278)
WordPress Plugin Import any XML or CSV File to WordPress Arbitrary File Upload (3.2.3)
MySQL CVE-2023-22058 Vulnerability (CVE-2023-22058)
Drupal Improper Input Validation Vulnerability (CVE-2012-1589)