*** This bug is a security vulnerability ***

You have been subscribed to a public security bug by Marc Deslauriers 
(mdeslaur):

https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-15562

# Description #

An issue was discovered in Roundcube Webmail before 1.2.11, 1.3.x before
1.3.14, and 1.4.x before 1.4.7. It allows XSS via a crafted HTML e-mail
message, as demonstrated by a JavaScript payload in the xmlns (aka XML
namespace) attribute of a HEAD element when an SVG element exists.

** Affects: roundcube (Ubuntu)
     Importance: Undecided
         Status: New


** Tags: community-security
-- 
CVE-2020-15562: XSS in roundcube < 1.3.14
https://bugs.launchpad.net/bugs/1891869
You received this bug notification because you are a member of Ubuntu Bugs, 
which is subscribed to the bug report.

-- 
ubuntu-bugs mailing list
ubuntu-bugs@lists.ubuntu.com
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs

Reply via email to