{"resultsPerPage":1,"startIndex":0,"totalResults":1,"format":"NVD_CVE","version":"2.0","timestamp":"2026-09-21T03:11:17.137","vulnerabilities":[{"cve":{"id":"CVE-2023-5631","sourceIdentifier":"security@eset.com","published":"2023-10-18T15:15:08.727","lastModified":"2026-06-17T06:48:58.673","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"Roundcube before 1.4.15, 1.5.x before 1.5.5, and 1.6.x before 1.6.4 allows stored XSS via an HTML e-mail message with a crafted SVG document because of program/lib/Roundcube/rcube_washtml.php behavior. This could allow a remote attacker\n\nto load arbitrary JavaScript code."},{"lang":"es","value":"Roundcube anterior a 1.4.15, 1.5.x anterior a 1.5.5 y 1.6.x anterior a 1.6.4 permiten almacenar XSS a través de un mensaje de correo electrónico HTML con un documento SVG manipulado debido al comportamiento de program/lib/Roundcube/rcube_washtml.php. Esto podría permitir que un atacante remoto cargue código JavaScript arbitrario."}],"affected":[{"source":"security@eset.com","affectedData":[{"vendor":"Roundcube","product":"Roundcubemail","defaultStatus":"unaffected","repo":"https://github.com/roundcube/roundcubemail","versions":[{"version":"1.6.0","lessThan":"1.6.3","versionType":"semver","status":"affected"},{"version":"1.5.0","lessThan":"1.5.4","versionType":"semver","status":"affected"},{"version":"1.4.0","lessThan":"1.5.14","versionType":"semver","status":"affected"},{"version":"1.6.4","status":"unaffected"},{"version":"1.5.5","status":"unaffected"},{"version":"1.5.15","status":"unaffected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"security@eset.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","baseScore":6.1,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":2.7},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N","baseScore":5.4,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.3,"impactScore":2.7}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2023-11-15T16:39:21.592115Z","id":"CVE-2023-5631","options":[{"exploitation":"active"},{"automatable":"no"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"cisaExploitAdd":"2023-10-26","cisaActionDue":"2023-11-16","cisaRequiredAction":"Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.","cisaVulnerabilityName":"Roundcube Webmail Persistent Cross-Site Scripting (XSS) Vulnerability","weaknesses":[{"source":"security@eset.com","type":"Secondary","description":[{"lang":"en","value":"CWE-79"}]},{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-79"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:roundcube:webmail:*:*:*:*:*:*:*:*","versionEndExcluding":"1.4.15","matchCriteriaId":"4A35A7DC-58C4-43F7-A66C-229B0A409224"},{"vulnerable":true,"criteria":"cpe:2.3:a:roundcube:webmail:*:*:*:*:*:*:*:*","versionStartIncluding":"1.5.0","versionEndExcluding":"1.5.5","matchCriteriaId":"AF32BDE4-0C58-4D19-9E7C-CC0C0B22DF51"},{"vulnerable":true,"criteria":"cpe:2.3:a:roundcube:webmail:*:*:*:*:*:*:*:*","versionStartIncluding":"1.6.0","versionEndExcluding":"1.6.4","matchCriteriaId":"BBAB5ECE-B692-46C2-A3EF-6BC52E4F3C3B"}]}]},{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:*","matchCriteriaId":"07B237A9-69A3-4A9C-9DA0-4E06BD37AE73"},{"vulnerable":true,"criteria":"cpe:2.3:o:debian:debian_linux:11.0:*:*:*:*:*:*:*","matchCriteriaId":"FA6FEEC2-9F11-4643-8827-749718254FED"},{"vulnerable":true,"criteria":"cpe:2.3:o:debian:debian_linux:12.0:*:*:*:*:*:*:*","matchCriteriaId":"46D69DCC-AE4D-4EA5-861C-D60951444C6C"},{"vulnerable":true,"criteria":"cpe:2.3:o:fedoraproject:fedora:39:*:*:*:*:*:*:*","matchCriteriaId":"B8EDB836-4E6A-4B71-B9B2-AA3E03E0F646"}]}]}],"references":[{"url":"http://www.openwall.com/lists/oss-security/2023/11/01/1","source":"security@eset.com","tags":["Mailing List","Third Party Advisory"]},{"url":"http://www.openwall.com/lists/oss-security/2023/11/01/3","source":"security@eset.com","tags":["Mailing List","Third Party Advisory"]},{"url":"http://www.openwall.com/lists/oss-security/2023/11/17/2","source":"security@eset.com","tags":["Mailing List","Third Party Advisory"]},{"url":"https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1054079","source":"security@eset.com","tags":["Mailing List","Patch"]},{"url":"https://github.com/roundcube/roundcubemail/commit/41756cc3331b495cc0b71886984474dc529dd31d","source":"security@eset.com","tags":["Patch"]},{"url":"https://github.com/roundcube/roundcubemail/commit/6ee6e7ae301e165e2b2cb703edf75552e5376613","source":"security@eset.com","tags":["Patch"]},{"url":"https://github.com/roundcube/roundcubemail/issues/9168","source":"security@eset.com","tags":["Exploit","Issue Tracking"]},{"url":"https://github.com/roundcube/roundcubemail/releases/tag/1.4.15","source":"security@eset.com","tags":["Release Notes"]},{"url":"https://github.com/roundcube/roundcubemail/releases/tag/1.5.5","source":"security@eset.com","tags":["Release Notes"]},{"url":"https://github.com/roundcube/roundcubemail/releases/tag/1.6.4","source":"security@eset.com","tags":["Release Notes"]},{"url":"https://lists.debian.org/debian-lts-announce/2023/10/msg00035.html","source":"security@eset.com","tags":["Mailing List","Third Party Advisory"]},{"url":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/LK67Q46OIEGJCRQUBHKLH3IIJTBNGGX4/","source":"security@eset.com","tags":["Mailing List"]},{"url":"https://roundcube.net/news/2023/10/16/security-update-1.6.4-released","source":"security@eset.com","tags":["Release Notes"]},{"url":"https://roundcube.net/news/2023/10/16/security-updates-1.5.5-and-1.4.15","source":"security@eset.com","tags":["Release Notes"]},{"url":"https://www.debian.org/security/2023/dsa-5531","source":"security@eset.com","tags":["Mailing List"]},{"url":"http://www.openwall.com/lists/oss-security/2023/11/01/1","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Mailing List","Third Party Advisory"]},{"url":"http://www.openwall.com/lists/oss-security/2023/11/01/3","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Mailing List","Third Party Advisory"]},{"url":"http://www.openwall.com/lists/oss-security/2023/11/17/2","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Mailing List","Third Party Advisory"]},{"url":"https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1054079","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Mailing List","Patch"]},{"url":"https://github.com/roundcube/roundcubemail/commit/41756cc3331b495cc0b71886984474dc529dd31d","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch"]},{"url":"https://github.com/roundcube/roundcubemail/commit/6ee6e7ae301e165e2b2cb703edf75552e5376613","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch"]},{"url":"https://github.com/roundcube/roundcubemail/issues/9168","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit","Issue Tracking"]},{"url":"https://github.com/roundcube/roundcubemail/releases/tag/1.4.15","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Release Notes"]},{"url":"https://github.com/roundcube/roundcubemail/releases/tag/1.5.5","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Release Notes"]},{"url":"https://github.com/roundcube/roundcubemail/releases/tag/1.6.4","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Release Notes"]},{"url":"https://lists.debian.org/debian-lts-announce/2023/10/msg00035.html","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Mailing List","Third Party Advisory"]},{"url":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/LK67Q46OIEGJCRQUBHKLH3IIJTBNGGX4/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Mailing List"]},{"url":"https://roundcube.net/news/2023/10/16/security-update-1.6.4-released","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Release Notes"]},{"url":"https://roundcube.net/news/2023/10/16/security-updates-1.5.5-and-1.4.15","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Release Notes"]},{"url":"https://www.debian.org/security/2023/dsa-5531","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Mailing List"]},{"url":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2023-5631","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","tags":["US Government Resource"]}]}}]}