CVE-2023-43770 is a Cross-Site Scripting (XSS) vulnerability affecting Roundcube webmail versions before 1.4.14, 1.5.4, and 1.6.3, specifically impacting the handling of crafted links within plain text email messages. This medium-severity vulnerability (CVSS 6.1) can be exploited remotely with low complexity, requiring user interaction, and could lead to information disclosure and limited integrity impact. Notably, this CVE is actively exploited in the wild, as confirmed by its inclusion in CISA's KEV catalog, and has garnered significant community discussion and media coverage, including reports of Russian APT groups leveraging it in targeted attacks. Despite active exploitation, no public exploit code is currently available on platforms like Metasploit or ExploitDB.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.4.14CPE matchmatch criteria | cpe:2.3:a:roundcube:webmail:*:*:*:*:*:*:*:* | ||
>= 1.5.0, < 1.5.4CPE matchmatch criteria | cpe:2.3:a:roundcube:webmail:*:*:*:*:*:*:*:* | ||
>= 1.6.0, < 1.6.3CPE matchmatch criteria | cpe:2.3:a:roundcube:webmail:*:*:*:*:*:*:*:* | ||
10.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.