EXPOSURES › CVE-2023-43770
CVE-2023-43770
HIGH ⌖ ON CISA KEV · EXPLOITEDRoundcube Webmail servers are actively exploited via a persistent XSS vulnerability that enables remote code execution.
CVE-2023-43770 allows attackers to inject malicious links into plain-text messages, leading to information disclosure and remote code execution on over 84,000 servers. DIB organizations using Roundcube Webmail face immediate CMMC/NIST 800-171 exposure due to the active exploitation of this unpatched vulnerability.
Shame score — The vulnerability is actively exploited in the wild and affects a massive number of servers, indicating widespread neglect of patch management.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Roundcube Webmail contains a persistent cross-site scripting (XSS) vulnerability that can lead to information disclosure via malicious link references in plain/text messages.