Description
Roundcube before 1.4.15, 1.5.x before 1.5.5, and 1.6.x before 1.6.4 allows stored XSS via an HTML e-mail message with a crafted SVG document because of program/lib/Roundcube/rcube_washtml.php behavior. This could allow a remote attacker to load arbitrary JavaScript code.
Remediation
References
Related Vulnerabilities
WordPress Plugin TagNinja 'id' Parameter Cross-Site Scripting (1.0)
WordPress Plugin Responsive WordPress Slider-Avartan Slider Lite Cross-Site Scripting (1.4)
WordPress Plugin Forms:3rd-Party Inject Results Cross-Site Scripting (0.2)
Moodle Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2012-4403)
WordPress Plugin Contact Form Check Tester Cross-Site Scripting (1.0.2)