EXPOSURES › CVE-2023-5631
CVE-2023-5631
HIGH ⌖ ON CISA KEV · EXPLOITEDRoundcube Webmail XSS vulnerability exposed in 84,000 servers
A persistent XSS vulnerability in Roundcube Webmail allows remote code execution, exposing over 84,000 servers to active exploitation. This poses a significant risk to DIB organizations, as it can lead to data breaches and unauthorized access. Immediate action is required to patch and secure affected systems.
Shame score — The vulnerability was actively exploited, affecting a large number of servers, and the lack of a patch for over a year indicates negligence.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Roundcube Webmail contains a persistent cross-site scripting (XSS) vulnerability that allows a remote attacker to run malicious JavaScript code.