CVE-2015-1433
EPSS 0.68%
Description
program/lib/Roundcube/rcube_washtml.php in Roundcube before 1.0.5 does not properly quote strings, which allows remote attackers to conduct cross-site scripting (XSS) attacks via the style attribute in an email.
How to fix CVE-2015-1433
To remediate CVE-2015-1433, upgrade the affected package to a fixed version below.
- Debian/roundcube—upgrade to 0.9.5+dfsg1-4.2 or later
Is CVE-2015-1433 being exploited?
Low — EPSS is 0.7%, meaning exploitation activity has not been observed at scale.
Affected packages (1)
- from 0, < 0.9.5+dfsg1-4.2