ZeroHour

CVE-2024-37383

KEVmass1

Cross-Site Scripting in Roundcube Webmail via SVG animate attributes

CISA: RoundCube Webmail Cross-Site Scripting (XSS) Vulnerability

CVSS 3.1
6.1 medium
EPSS
73%p99
Published
()
KEV added
AI analysis

CVE-2024-37383 is a cross-site scripting vulnerability (CWE-79) in Roundcube Webmail caused by insufficient handling of SVG 'animate' attributes when HTML email content is rendered. An attacker triggers it by sending a crafted HTML email containing a malicious SVG animate element; when the recipient views the message in Roundcube, attacker-controlled JavaScript executes in the context of the victim's webmail session. Successful exploitation allows theft of session cookies and credentials, access to mailbox contents, sending mail as the victim, or redirection to phishing pages, and has been used in campaigns that steal credentials and email. All Roundcube Webmail deployments before 1.5.7 and 1.6.x before 1.6.7 are affected, including Roundcube packages shipped with Debian; because the attack requires only viewing a malicious email, any exposed webmail user is a potential victim. The flaw is under active exploitation: unknown threat actors have used it in phishing campaigns, it carries an EPSS of 73.3%, and CISA added it to the Known Exploited Vulnerabilities catalog on 2024-10-24.

What to do: Upgrade Roundcube to version 1.5.7 or 1.6.7 (or later) immediately; Debian users should install the updated roundcube package from their repository. Organizations subject to CISA BOD 22-01 must apply vendor mitigations or discontinue use per the KEV entry. Review webmail logs for phishing emails containing SVG animate elements and investigate for credential theft or anomalous mailbox activity.

Affected
Roundcube Webmailbefore 1.5.7 and 1.6.x before 1.6.7 (i.e., 1.6.0 through 1.6.6 and earlier releases)
Debian Linux (Roundcube webmail package)
Estimated exposure
masslikely millions of webmail users across hundreds of thousands of deployed instances, with tens of thousands of instances internet-exposed — Roundcube is the dominant open-source webmail bundled with hosting control panels and used by ISPs, universities and enterprises, and public internet scans show tens of thousands of exposed instances, implying a user base well above one…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Roundcube Webmail before 1.5.7 and 1.6.x before 1.6.7 allows XSS via SVG animate attributes.

CISA Known Exploited Vulnerability
Affected
Roundcube Webmail
Required action
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Due date
Ransomware use
Unknown
Vendors
roundcubedebian
Products
webmail, debian linux
Weakness
CWE-79
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

In the news