CISA KEV · Known exploitedMedium
CVE-2024-37383
Roundcube Webmail
Roundcube Webmail before 1.5.7 and 1.6.x before 1.6.7 allows XSS via SVG animate attributes.
- CVSS
- 6.1
- EPSS
- 73.3% 99.4% percentile
- CISA KEV
- Listed
- Published
- 2024.06.07
Roundcube Webmail before 1.5.7 and 1.6.x before 1.6.7 allows XSS via SVG animate attributes.
CISA has listed this vulnerability in the Known Exploited Vulnerabilities catalog.
Roundcube Webmail before 1.5.7 and 1.6.x before 1.6.7 allows XSS via SVG animate attributes.
Confirm exposure before applying a vendor-supported change.
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Due date: 2024.11.14Confirm that Roundcube Webmail and an affected version are present.
Combine exploitation signals with asset exposure and business criticality.
Follow the vendor advisory or supported update path and preserve rollback options.
Recheck the version, service health, access paths, and relevant logs.