RULE(RULE ID:505894)

Rule General Information
Release Date: 2025-03-11
Rule Name: Roundcube Webmail Persistent Cross Site Scripting Vulnerability (CVE-2024-37383)
Severity:
CVE ID:
Rule Protection Details
Description: Roundcube Webmail before 1.5.7 and 1.6.x before 1.6.7 allows XSS via SVG animate attributes.
Impact: An attacker can conduct a cross-site scripting attack to inject malicious client-side scripts into web pages viewed by other users, or to bypass access controls such as the same-origin policy, if affected version is installed.
Affected OS: Windows, Linux, Others
Reference: https://github.com/roundcube/roundcubemail/commit/43aaaa528646877789ec028d87924ba1accf5242
https://github.com/roundcube/roundcubemail/releases/tag/1.5.7
https://github.com/roundcube/roundcubemail/releases/tag/1.6.7
https://lists.debian.org/debian-lts-announce/2024/06/msg00008.html
Solutions
Please refer to announcements or patches release by the vendor: https://github.com/roundcube/roundcubemail/commit/43aaaa528646877789ec028d87924ba1accf5242