Vulnerabilities > Roundcube > Webmail
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2016-01-29 | CVE-2015-8793 | Cross-site Scripting vulnerability in Roundcube Webmail Cross-site scripting (XSS) vulnerability in program/include/rcmail.php in Roundcube before 1.0.6 and 1.1.x before 1.1.2 allows remote attackers to inject arbitrary web script or HTML via the _mbox parameter in a mail task to the default URL, a different vulnerability than CVE-2011-2937. | 6.1 |