ZeroHour

CVE-2023-43770

KEVmass

Persistent Cross-Site Scripting in Roundcube Webmail (Exploited in the Wild)

CISA: Roundcube Webmail Persistent Cross-Site Scripting (XSS) Vulnerability

CVSS 3.1
6.1 medium
EPSS
58%p99
Published
()
KEV added
AI analysis

Roundcube Webmail versions before 1.4.14, 1.5.x before 1.5.4, and 1.6.x before 1.6.3 contain a persistent cross-site scripting (XSS) flaw (CWE-79) caused by how program/lib/Roundcube/rcube_string_replacer.php converts plain text into clickable links. An attacker sends a text/plain email containing crafted links; when the recipient views the message, the crafted link text is turned into HTML that runs attacker-controlled script, which persists and executes in the victim's webmail session. Successful exploitation lets the attacker execute JavaScript with the victim's session, enabling mailbox access, theft of session credentials, and actions performed as the user (CVSS 6.1, scope-changed with limited confidentiality and integrity impact). Anyone running an affected Roundcube instance is exposed, including the roundcube package shipped with Debian Linux. The flaw is being actively exploited: CISA added it to the Known Exploited Vulnerabilities catalog on 2024-02-12, and EPSS assigns a 58.5% probability of exploitation within 30 days (99th percentile).

What to do: Upgrade Roundcube to 1.4.14, 1.5.4, or 1.6.3 (or later, per branch), or install the updated roundcube package on Debian. Because the bug is in CISA's KEV catalog, U.S. federal agencies must apply the vendor fix by the catalog due date, and other defenders should prioritize patching internet-facing webmail servers. Review webmail access logs for suspicious message views or account activity, and consider forcing session re-authentication for accounts that opened crafted plain-text messages.

Affected
Roundcube Webmailbefore 1.4.14; 1.5.x before 1.5.4; 1.6.x before 1.6.3
Debian Linux (roundcube package)
Estimated exposure
massplausibly millions of users across tens of thousands of internet-exposed Roundcube instances (estimate) — Roundcube is the bundled/default webmail client in common hosting control panels and is widely self-hosted by hosting providers, ISPs, and universities, and public internet scans have catalogued tens of thousands of reachable Roundcube…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Roundcube before 1.4.14, 1.5.x before 1.5.4, and 1.6.x before 1.6.3 allows XSS via text/plain e-mail messages with crafted links because of program/lib/Roundcube/rcube_string_replacer.php behavior.

CISA Known Exploited Vulnerability
Affected
Roundcube Webmail
Required action
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Due date
Ransomware use
Unknown
Vendors
roundcubedebian
Products
webmail, debian linux
Weakness
CWE-79
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

In the news