EXPOSURES › CVE-2024-37383
CVE-2024-37383
HIGH ⌖ ON CISA KEV · EXPLOITEDRoundCube Webmail exploited a remote XSS flaw in SVG animate attributes affecting over 84,000 servers.
A remote attacker can execute arbitrary JavaScript via the SVG animate attribute, enabling potential privilege escalation or data theft in webmail environments. DIB orgs must patch immediately as the flaw is actively exploited and linked to supply-chain risks, even though it is not explicitly ransomware-linked.
Shame score — The vendor shipped a widely deployed webmail product with a known, actively exploited remote code execution flaw that affects over 84,000 servers.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
RoundCube Webmail contains a cross-site scripting (XSS) vulnerability in the handling of SVG animate attributes that allows a remote attacker to run malicious JavaScript code.