Description
Roundcube Webmail before 1.5.12 and 1.6 before 1.6.12 is prone to a Cross-Site-Scripting (XSS) vulnerability via the animate tag in an SVG document.
Remediation
References
Related Vulnerabilities
WordPress Plugin Integration for HubSpot and WooCommerce Cross-Site Scripting (1.0.4)
PHP Insufficient Verification of Data Authenticity Vulnerability (CVE-2024-5458)
Werkzeug WSGI CVE-2023-23934 Vulnerability (CVE-2023-23934)
WordPress 'comment_post_ID' Parameter SQL Injection Vulnerability (3.0.4)