Description
A Cross-Site Scripting vulnerability in Roundcube through 1.5.7 and 1.6.x through 1.6.7 allows a remote attacker to steal and send emails of a victim via a crafted e-mail message that abuses a Desanitization issue in message_body() in program/actions/mail/show.php.
Remediation
References
Related Vulnerabilities
WordPress Plugin YITH WooCommerce Product Add-Ons Cross-Site Scripting (2.2.2)
Squid Improper Input Validation Vulnerability (CVE-2016-2572)
WordPress Plugin WP OAuth Server (OAuth Authentication) Cross-Site Scripting (4.2.1)
WordPress Plugin WP Login Security and History Cross-Site Request Forgery (1.0)