Zurück zur CVE-Übersicht
CVE-2026-48848
HIGH(7.2)CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N
Risk Signal Score18/100 — NIEDRIG
- CVSS 7.2 — Hoch
Erwähnungen (letzte 60 Tage)
Artikel
EPSS-Score
0.4%
Exploit-Wahrscheinlichkeit (30 Tage)
CVSS Score
7.2
Technische Schwere
Beschreibung
Roundcube Webmail 1.6.x before 1.6.16 and 1.7.x before 1.7 has insufficient HTML sanitization that could lead to Cascading Style Sheets (CSS) injection via an SVG document that has an animate element with the attributeName attribute.
Referenzen
- https://github.com/roundcube/roundcubemail/commit/58e5263f341e6a418774fb6d264366...
- https://github.com/roundcube/roundcubemail/commit/c960d102472dc579e15907d5bcdc31...
- https://github.com/roundcube/roundcubemail/releases/tag/1.6.16
- https://github.com/roundcube/roundcubemail/releases/tag/1.7.1
- https://roundcube.net/news/2026/05/24/security-updates-1.6.16-and-1.7.1