Roundcube before 1.4.13 and 1.5.x before 1.5.2 allows XSS via an HTML e-mail message with crafted Cascading Style Sheets (CSS) token sequences.
References
Configurations
History
No history.
Information
Published : 2022-01-06 05:15
Updated : 2024-11-21 06:33
NVD link : CVE-2021-46144
Mitre link : CVE-2021-46144
CVE.ORG link : CVE-2021-46144
JSON object : View
Products Affected
roundcube
- roundcube
debian
- debian_linux
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')