Description
Roundcube before 1.4.15, 1.5.x before 1.5.5, and 1.6.x before 1.6.4 allows stored XSS via an HTML e-mail message with a crafted SVG document because of program/lib/Roundcube/rcube_washtml.php behavior. This could allow a remote attacker to load arbitrary JavaScript code.
Remediation
References
Related Vulnerabilities
WordPress Plugin Dynamic Widgets 'id' Parameter Cross-Site Scripting (1.5.1)
Joomla! Core 3.x.x Cross-Site Scripting (3.0.0 - 3.9.19)
Piwigo URL Redirection to Untrusted Site ('Open Redirect') Vulnerability (CVE-2017-9464)
WordPress Plugin SI CAPTCHA Anti-Spam Serving Spam (3.0.2)
Jboss EAP Permissions, Privileges, and Access Controls Vulnerability (CVE-2010-0738)