CVE-2018-19206
—CVSS 3.0
6.1 medium
EPSS
56%p99
Published
()
Modified
Description
steps/mail/func.inc in Roundcube before 1.3.8 has XSS via crafted use of , as demonstrated by an onload attribute in a BODY element, within an HTML attachment.
In the news0 stories
No ingested article mentions this CVE yet.