Vigil@nce - Roundcube Webmail: Cross Site Scripting via HEAD SVG XML Namespace, analyzed on 08/07/2020

Vigil@nce - Roundcube Webmail: Cross Site Scripting via HEAD SVG XML Namespace, analyzed on 08/07/2020

The Vigil@nce team watches public vulnerabilities impacting your computers, and then offers security solutions, a vigilance database and tools to fix them.







Synthesis of the vulnerability 


An attacker can trigger a Cross Site Scripting via HEAD SVG XML Namespace of Roundcube Webmail, in order to run JavaScript code in the context of the web site.Vulnerable products: Debian, Fedora.Severity of this weakness: 2/4.Creation date: 08/07/2020.Références of this bulletin: CVE-2020-15562, DSA-4720-1, FEDORA-2020-4ccfee6d83, FEDORA-2020-5352732865, VIGILANCE-VUL-32748.

Description of the vulnerability 


An attacker can trigger a Cross Site Scripting via HEAD SVG XML Namespace of Roundcube Webmail, in order to run JavaScript code in the context of the web site.Full bulletin, software filtering, emails, fixes, ... (Request your free trial)

This cybersecurity note impacts software or systems such as Debian, Fedora.

Our Vigil@nce team determined that the severity of this computer weakness announce is medium.

The trust level is of type confirmed by the editor, with an origin of document.

An attacker with a expert ability can exploit this cybersecurity vulnerability.

Solutions for this threat 


Debian 10: new roundcube packages.New packa ..

Support the originator by clicking the read the rest link below.