UBUNTU-CVE-2023-47272
Dashboard / Vulnerabilities / UBUNTU-CVE-2023-47272
UBUNTU-CVE-2023-47272
Summary:
Details: Roundcube 1.5.x before 1.5.6 and 1.6.x before 1.6.5 allows XSS via a Content-Type or Content-Disposition header (used for attachment preview or download).
References: https://ubuntu.com/security/CVE-2023-47272, https://github.com/roundcube/roundcubemail/commit/81ac3c342a4f288deb275590895b52ec3785cf8a, https://github.com/roundcube/roundcubemail/commit/5ec496885e18ec6af956e8c0d627856c2257ba2d, https://github.com/roundcube/roundcubemail/releases/tag/1.5.6, https://github.com/roundcube/roundcubemail/releases/tag/1.6.5, https://www.cve.org/CVERecord?id=CVE-2023-47272, https://ubuntu.com/security/notices/USN-6848-1
Affected packages
Package
Name: roundcube
Purl: pkg:deb/ubuntu/[email protected]+dfsg.1-1ubuntu0.1~esm4?arch=source&distro=esm-apps/focal
Affected ranges
Type: ECOSYSTEM
Events:
