Skip to content
COOEY

EXPOSURES › CVE-2020-13965

CVE-2020-13965

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2024-06-26 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2020-13965 ↗
⚡ RCE ⌖ EXPLOITED IN THE WILD SHAME 45/100 exploited-in-wildrceunpatched

Roundcube Webmail exploited via CVE-2020-13965 allows remote attackers to execute arbitrary code through malicious XML attachments.

This vulnerability enables remote code execution via XML attachments, exposing over 84,000 Roundcube Webmail servers to exploitation. DIB organizations using Roundcube must immediately patch or disable the product to prevent unauthorized access to sensitive data.

Shame score — The vulnerability was actively exploited in the wild but was not zero-day, and the vendor did not disclose it responsibly.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

Roundcube Webmail contains a cross-site scripting (XSS) vulnerability that allows a remote attacker to manipulate data via a malicious XML attachment.

AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.