CVE-2023-5631mediumunder attackCWE-79

CVE-2023-5631: medium-severity vulnerability in Roundcubemail

Stored XSS vulnerability in Roundcube

Published · Updated

65Vexday Risk Score

Prioritize patching. It under exploitation confirmed by CISA.

ssvc Actcvss 6.1epss 76%
from disclosure to weapon
Published on NVDOct 18
CISA KEV+8d
exploitation probability
76%top 1% of all CVEs
observed exploitation
yesCISA + VulnCheck
What the vendors declare (VEX)

Official vendor statements in CSAF/VEX format: whether their product is affected, already fixed, or ruled out — and why. These are the vendor's assertions, not Vexday's judgment.

Not affected
1 product — because the vulnerable code is not present in the product
red_hat_products
Action required by CISAfederal deadline: 2023-11-16

Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

In short

Roundcube email clients before certain versions allow attackers to inject malicious JavaScript code through specially crafted HTML emails with SVG documents. This code runs when a user views the email, potentially compromising their account or stealing sensitive information.

Technical detail

Stored XSS vulnerability in rcube_washtml.php fails to properly sanitize SVG elements within HTML email messages, allowing remote attackers to inject arbitrary JavaScript. Attack vector is user email viewing; no authentication required beyond receiving the malicious message. Impact includes session hijacking and credential theft.

Summary generated and translated by AI from the official description.

The full analysis of this CVE is available in Portuguese →

Roundcube before 1.4.15, 1.5.x before 1.5.5, and 1.6.x before 1.6.4 allows stored XSS via an HTML e-mail message with a crafted SVG document because of program/lib/Roundcube/rcube_washtml.php behavior. This could allow a remote attacker to load arbitrary JavaScript code.
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N