EUVD-2024-39391
A Cross-Site Scripting vulnerability in Roundcube through 1.5.7 and 1.6.x through 1.6.7 allows a remote attacker to steal and send emails of a victim via a crafted e-mail message that abuses a Desanitization issue in message_body() in program/actions/mail/show.php.
- EUVD state
- Present in the current official mapping
- Known exploitation
- Recorded by ENISA since 9 Jun 2025. Evidence sources: cisa_kev, eukev_kev.
- ENISA score
- 9.3 · CVSS 3.1
- Advisory evidence
- 4 linked advisory records
Only statements that explicitly mention a fix, patch, update, workaround or mitigation are shown here.
- csaf_ncscnl · NCSC-2024-0326Kwetsbaarheden verholpen in RoundCube Webmail
- csaf_opensuse · openSUSE-SU-2024:0328-1Security update for roundcubemail
