Cross-Site Scripting (XSS) vulnerability in Roundcube Webmail 1.6.9 allows remote authenticated users to upload a malicious file as an email attachment, leading to the triggering of the XSS by visiting the SENT session.
Metrics
Affected Vendors & Products
References
History
Wed, 12 Feb 2025 20:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Weaknesses | CWE-80 | |
Metrics |
cvssV3_1
|
Mon, 03 Feb 2025 19:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | Cross-Site Scripting (XSS) vulnerability in Roundcube Webmail 1.6.9 allows remote authenticated users to upload a malicious file as an email attachment, leading to the triggering of the XSS by visiting the SENT session. | |
References |
|

Status: PUBLISHED
Assigner: mitre
Published: 2025-02-03T00:00:00.000Z
Updated: 2025-02-12T19:18:08.984Z
Reserved: 2025-01-09T00:00:00.000Z
Link: CVE-2024-57004

Updated: 2025-02-05T16:14:01.847Z

Status : Awaiting Analysis
Published: 2025-02-03T19:15:12.777
Modified: 2025-02-12T20:15:35.330
Link: CVE-2024-57004

No data.