Description
program/lib/Roundcube/rcube_washtml.php in Roundcube before 1.0.5 does not properly quote strings, which allows remote attackers to conduct cross-site scripting (XSS) attacks via the style attribute in an email.
Remediation
References
Related Vulnerabilities
WordPress 4.2.x Prototype Pollution (4.2 - 4.2.31)
WordPress Plugin Photo Gallery by 10Web-Mobile-Friendly Image Gallery Cross-Site Scripting (1.5.75)
WordPress Plugin WP Offload SES Lite Cross-Site Scripting (1.4.4)
MySQL CVE-2022-21352 Vulnerability (CVE-2022-21352)
phpMyAdmin Improper Control of Generation of Code ('Code Injection') Vulnerability (CVE-2011-2505)