Skip to content
COOEY

EXPOSURES › CVE-2020-35730

CVE-2020-35730

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2023-06-22 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2020-35730 ↗
⚡ RCE ⌖ EXPLOITED IN THE WILD SHAME 72/100 exploited-in-wildunpatched

Roundcube Webmail XSS vulnerability exposed in 84,000 servers

An XSS vulnerability in Roundcube Webmail allows attackers to inject malicious JavaScript, exposing over 84,000 servers to remote code execution. This is a high-severity issue, as it enables attackers to send malicious emails and potentially gain control of the affected systems. DIB organizations should ensure their systems are patched and monitor for any signs of exploitation.

Shame score — The vulnerability was actively exploited, affecting a large number of servers, and the lack of a patch for over a year indicates negligence.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

Roundcube Webmail contains a cross-site scripting (XSS) vulnerability that allows an attacker to send a plain text e-mail message with Javascript in a link reference element that is mishandled by linkref_addinindex in rcube_string_replacer.php.

AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.