Vulnerability Name:

CVE-2020-35730 (CCN-193983)

Assigned:2020-12-12
Published:2020-12-12
Updated:2022-04-24
Summary:An XSS issue was discovered in Roundcube Webmail before 1.2.13, 1.3.x before 1.3.16, and 1.4.x before 1.4.10. The attacker can send a plain text e-mail message, with JavaScript in a link reference element that is mishandled by linkref_addindex in rcube_string_replacer.php.
CVSS v3 Severity:6.1 Medium (CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N)
5.8 Medium (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N/E:H/RL:O/RC:C)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): Required
Scope:Scope (S): Changed
Impact Metrics:Confidentiality (C): Low
Integrity (I): Low
Availibility (A): None
6.1 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N)
5.8 Medium (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N/E:H/RL:O/RC:C)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): Required
Scope:Scope (S): Changed
Impact Metrics:Confidentiality (C): Low
Integrity (I): Low
Availibility (A): None
CVSS v2 Severity:4.3 Medium (CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Medium
Authentication (Au): None
Impact Metrics:Confidentiality (C): None
Integrity (I): Partial
Availibility (A): None
5.5 Medium (CCN CVSS v2 Vector: AV:N/AC:L/Au:S/C:P/I:P/A:N)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Athentication (Au): Single_Instance
Impact Metrics:Confidentiality (C): Partial
Integrity (I): Partial
Availibility (A): None
Vulnerability Type:CWE-79
Vulnerability Consequences:Cross-Site Scripting
References:Source: MITRE
Type: CNA
CVE-2020-35730

Source: CCN
Type: Debian Bug report logs - #978491
roundcube: CVE-2020-35730: XSS vulnerability via malious HTML or plaintext messages

Source: CONFIRM
Type: Issue Tracking, Mailing List, Third Party Advisory
https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=978491

Source: XF
Type: UNKNOWN
roundcube-cve202035730-xss(193983)

Source: CCN
Type: Rroundcube GIT Repository
Fix cross-site scripting (XSS) via HTML or Plain text messages

Source: CONFIRM
Type: Patch, Third Party Advisory
https://github.com/roundcube/roundcubemail/compare/1.4.9...1.4.10

Source: CONFIRM
Type: Release Notes, Third Party Advisory
https://github.com/roundcube/roundcubemail/releases/tag/1.2.13

Source: CONFIRM
Type: Release Notes, Third Party Advisory
https://github.com/roundcube/roundcubemail/releases/tag/1.3.16

Source: CONFIRM
Type: Release Notes, Third Party Advisory
https://github.com/roundcube/roundcubemail/releases/tag/1.4.10

Source: FEDORA
Type: Mailing List, Third Party Advisory
FEDORA-2021-73359af51c

Source: FEDORA
Type: Mailing List, Third Party Advisory
FEDORA-2021-2cb0643316

Source: MISC
Type: Vendor Advisory
https://roundcube.net/download/

Source: MISC
Type: Broken Link
https://www.alexbirnberg.com/roundcube-xss.html

Source: CCN
Type: WhiteSource Vulnerability Database
CVE-2020-35730

Vulnerable Configuration:Configuration 1:
  • cpe:/a:roundcube:webmail:*:*:*:*:*:*:*:* (Version < 1.2.13)
  • OR cpe:/a:roundcube:webmail:*:*:*:*:*:*:*:* (Version >= 1.3.0 and < 1.3.16)
  • OR cpe:/a:roundcube:webmail:*:*:*:*:*:*:*:* (Version >= 1.4 and < 1.4.10)

  • Configuration 2:
  • cpe:/o:fedoraproject:fedora:32:*:*:*:*:*:*:*
  • OR cpe:/o:fedoraproject:fedora:33:*:*:*:*:*:*:*

  • Configuration 3:
  • cpe:/o:debian:debian_linux:9.0:*:*:*:*:*:*:*

  • * Denotes that component is vulnerable
    Oval Definitions
    Definition IDClassTitleLast Modified
    oval:org.opensuse.security:def:113341
    P
    roundcubemail-1.4.11-1.3 on GA media (Moderate)
    2022-01-17
    oval:org.opensuse.security:def:100369
    P
    (Important)
    2021-12-22
    oval:org.opensuse.security:def:106748
    P
    Security update for mozilla-nss (Important)
    2021-12-06
    oval:org.opensuse.security:def:96405
    P
    Security update for roundcubemail (Important)
    2021-07-09
    oval:org.opensuse.security:def:109752
    P
    Security update for roundcubemail (Important)
    2021-07-09
    oval:org.opensuse.security:def:11095
    P
    Security update for roundcubemail (Important)
    2021-07-09
    oval:org.opensuse.security:def:103095
    P
    Security update for roundcubemail (Important)
    2021-07-09
    oval:org.opensuse.security:def:109845
    P
    Security update for roundcubemail (Important)
    2021-07-06
    oval:org.opensuse.security:def:103188
    P
    Security update for roundcubemail (Important)
    2021-07-06
    oval:org.opensuse.security:def:11236
    P
    Security update for roundcubemail (Important)
    2021-07-06
    oval:org.opensuse.security:def:96498
    P
    Security update for roundcubemail (Important)
    2021-07-06
    oval:org.opensuse.security:def:103187
    P
    Security update for roundcubemail (Important)
    2021-07-02
    oval:org.opensuse.security:def:11235
    P
    Security update for roundcubemail (Important)
    2021-07-02
    oval:org.opensuse.security:def:96497
    P
    Security update for roundcubemail (Important)
    2021-07-02
    oval:org.opensuse.security:def:109844
    P
    Security update for roundcubemail (Important)
    2021-07-02
    oval:org.opensuse.security:def:96496
    P
    Security update for roundcubemail (Important)
    2021-06-29
    oval:org.opensuse.security:def:109843
    P
    Security update for roundcubemail (Important)
    2021-06-29
    oval:org.opensuse.security:def:11233
    P
    Security update for roundcubemail (Important)
    2021-06-29
    oval:org.opensuse.security:def:103186
    P
    Security update for roundcubemail (Important)
    2021-06-29
    oval:org.opensuse.security:def:93656
    P
    Security update for roundcubemail (Important)
    2021-06-29
    oval:org.opensuse.security:def:11234
    P
    Security update for roundcubemail (Important)
    2021-06-29
    oval:org.opensuse.security:def:107035
    P
    Security update for roundcubemail (Important)
    2021-06-29
    oval:org.opensuse.security:def:111467
    P
    Security update for roundcubemail (Important)
    2021-06-27
    BACK
    roundcube webmail *
    roundcube webmail *
    roundcube webmail *
    fedoraproject fedora 32
    fedoraproject fedora 33
    debian debian linux 9.0