ZeroHour

CVE-2020-13965

KEV PoC mass

XSS via Malicious XML Attachment in Roundcube Webmail

CISA: Roundcube Webmail Cross-Site Scripting (XSS) Vulnerability

CVSS 3.1
6.1 medium
EPSS
77%p100
Published
()
KEV added
AI analysis

Roundcube Webmail before 1.3.12 and 1.4.x before 1.4.5 is vulnerable to cross-site scripting via malicious XML attachments, because text/xml is among the MIME types the client renders in the attachment preview, allowing embedded markup or script to execute in the victim's browser. An attacker triggers the flaw by emailing a crafted XML attachment and persuading a user to preview it. Successful exploitation lets the attacker run arbitrary JavaScript in the victim's webmail session, potentially hijacking the session, reading or manipulating mail, or acting as the user. Any Roundcube deployment running an affected version is exposed, including the Roundcube packages shipped in Debian and Fedora, though the share of installs still unpatched in 2024 is not documented in the available data. CISA added the flaw to its Known Exploited Vulnerabilities catalog on 2024-06-26, confirming exploitation in the wild, and a public proof-of-concept is available with EPSS at roughly 77% probability of exploitation within 30 days.

What to do: Upgrade Roundcube to 1.3.12 or later on the 1.3 branch, or 1.4.5 or later on the 1.4 branch. If immediate patching is not possible, apply vendor mitigations — such as removing text/xml from the MIME types permitted for attachment preview — or discontinue use of the product per CISA's required action. Audit mail servers and hosting panels for Roundcube versions and monitor for suspicious activity around XML attachment previews.

Affected
Roundcube Webmailbefore 1.3.12 and 1.4.x before 1.4.5
Debian Linux (Roundcube package)packages shipping Roundcube before 1.3.12 or 1.4.x before 1.4.5 (exact affected Debian releases not specified in source data)
fedoraproject Fedora (Roundcube package)packages shipping Roundcube before 1.3.12 or 1.4.x before 1.4.5 (exact affected Fedora releases not specified in source data)
Estimated exposure
massmillions of users across hundreds of thousands of deployments; count of currently unpatched instances unknown — Roundcube is bundled in Debian and Fedora repositories and is the default or standard webmail in many ISP, university, and hosting-provider mail stacks, giving it an install base commonly cited in the millions of users, though the fraction…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

An issue was discovered in Roundcube Webmail before 1.3.12 and 1.4.x before 1.4.5. There is XSS via a malicious XML attachment because text/xml is among the allowed types for a preview.

CISA Known Exploited Vulnerability
Affected
Roundcube Webmail
Required action
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Due date
Ransomware use
Unknown
Vendors
roundcubedebianfedoraproject
Products
webmail, debian linux, fedora
Weakness
CWE-79, CWE-80
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

In the news