EXPOSURES › CVE-2020-35730
CVE-2020-35730
HIGH ⌖ ON CISA KEV · EXPLOITEDRoundcube Webmail XSS vulnerability exposed in 84,000 servers
An XSS vulnerability in Roundcube Webmail allows attackers to inject malicious JavaScript, exposing over 84,000 servers to remote code execution. This is a high-severity issue, as it enables attackers to send malicious emails and potentially gain control of the affected systems. DIB organizations should ensure their systems are patched and monitor for any signs of exploitation.
Shame score — The vulnerability was actively exploited, affecting a large number of servers, and the lack of a patch for over a year indicates negligence.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Roundcube Webmail contains a cross-site scripting (XSS) vulnerability that allows an attacker to send a plain text e-mail message with Javascript in a link reference element that is mishandled by linkref_addinindex in rcube_string_replacer.php.