CVE-2023-5631: medium-severity vulnerability in Roundcubemail
Stored XSS vulnerability in Roundcube
Published · Updated
Prioritize patching. It under exploitation confirmed by CISA.
Official vendor statements in CSAF/VEX format: whether their product is affected, already fixed, or ruled out — and why. These are the vendor's assertions, not Vexday's judgment.
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Roundcube email clients before certain versions allow attackers to inject malicious JavaScript code through specially crafted HTML emails with SVG documents. This code runs when a user views the email, potentially compromising their account or stealing sensitive information.
Stored XSS vulnerability in rcube_washtml.php fails to properly sanitize SVG elements within HTML email messages, allowing remote attackers to inject arbitrary JavaScript. Attack vector is user email viewing; no authentication required beyond receiving the malicious message. Impact includes session hijacking and credential theft.
The full analysis of this CVE is available in Portuguese →