CVE-2020-13965 is a Cross-Site Scripting (XSS) vulnerability in Roundcube Webmail versions prior to 1.3.12 and 1.4.5, allowing attackers to execute malicious scripts via specially crafted XML attachments due to improper handling of text/xml previews. This medium-severity vulnerability (CVSS 6.1) can be exploited remotely with low complexity, requiring user interaction, and could lead to limited confidentiality and integrity impacts. Notably, this flaw is actively exploited in the wild, as confirmed by its presence in CISA's KEV catalog, and has garnered significant community discussion and media coverage, despite no public exploit code being readily available.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.3.12CPE matchmatch criteria | cpe:2.3:a:roundcube:webmail:*:*:*:*:*:*:*:* | ||
>= 1.4.0, < 1.4.5CPE matchmatch criteria | cpe:2.3:a:roundcube:webmail:*:*:*:*:*:*:*:* | ||
9.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:* | ||
10.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:* | ||
31CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:31:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.