Skip to content
COOEY

EXPOSURES › CVE-2024-37383

CVE-2024-37383

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2024-10-24 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2024-37383 ↗
⚡ RCE ⌖ EXPLOITED IN THE WILD SHAME 65/100 exploited-in-wildunpatchedransomware

RoundCube Webmail exploited a remote XSS flaw in SVG animate attributes affecting over 84,000 servers.

A remote attacker can execute arbitrary JavaScript via the SVG animate attribute, enabling potential privilege escalation or data theft in webmail environments. DIB orgs must patch immediately as the flaw is actively exploited and linked to supply-chain risks, even though it is not explicitly ransomware-linked.

Shame score — The vendor shipped a widely deployed webmail product with a known, actively exploited remote code execution flaw that affects over 84,000 servers.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

RoundCube Webmail contains a cross-site scripting (XSS) vulnerability in the handling of SVG animate attributes that allows a remote attacker to run malicious JavaScript code.

AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.