Candidate: CVE-2020-18670 PublicDate: 2021-06-24 19:15:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-18670 https://lorexxar.cn/2020/06/10/roundcube-mail-xss/#Store-Xss-in-installer-test-php https://github.com/roundcube/roundcubemail/issues/7406 https://roundcube.net/news/2020/06/02/security-updates-1.4.5-and-1.3.12 Description: Cross Site Scripting (XSS) vulneraibility in Roundcube mail .4.4 via database host and user in /installer/test.php. Ubuntu-Description: Notes: Mitigation: Bugs: Priority: medium Discovered-by: Assigned-to: CVSS: nvd: CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N [5.4 MEDIUM] Patches_roundcube: upstream: https://github.com/roundcube/roundcubemail/commit/655cfa50cc6ca10c86ff4fb183a31ad2255a8823 (1.3.x) upstream: https://github.com/roundcube/roundcubemail/commit/37e2bc745723ef6322f0f785aefd0b9313a40f19 (1.3.x) upstream: https://github.com/roundcube/roundcubemail/commit/20ae604b9fe061dbb22074577d38dbe293224ef6 (1.4.x) upstream: https://github.com/roundcube/roundcubemail/commit/4beec65d40c5e5b1f2bace935c110baf05e10ae5 (1.4.x) upstream_roundcube: released (1.3.12, 1.4.5) trusty_roundcube: ignored (out of standard support) trusty/esm_roundcube: DNE (trusty was needed) xenial_roundcube: ignored (out of standard support, was needed) bionic_roundcube: needed focal_roundcube: needed groovy_roundcube: ignored (reached end-of-life) hirsute_roundcube: ignored (reached end-of-life) impish_roundcube: not-affected (1.4.11+dfsg.1-4) jammy_roundcube: not-affected (1.5.0+dfsg.1-2) devel_roundcube: not-affected (1.5.0+dfsg.1-2)