Skip to content
COOEY

EXPOSURES › CVE-2023-5631

CVE-2023-5631

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2023-10-26 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2023-5631 ↗
⚡ RCE ⌖ EXPLOITED IN THE WILD SHAME 72/100 exploited-in-wildunpatched

Roundcube Webmail XSS vulnerability exposed in 84,000 servers

A persistent XSS vulnerability in Roundcube Webmail allows remote code execution, exposing over 84,000 servers to active exploitation. This poses a significant risk to DIB organizations, as it can lead to data breaches and unauthorized access. Immediate action is required to patch and secure affected systems.

Shame score — The vulnerability was actively exploited, affecting a large number of servers, and the lack of a patch for over a year indicates negligence.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

Roundcube Webmail contains a persistent cross-site scripting (XSS) vulnerability that allows a remote attacker to run malicious JavaScript code.

AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.