Description
Cross-site scripting (XSS) vulnerability in program/include/rcmail.php in Roundcube Webmail 1.1.x before 1.1.2 allows remote attackers to inject arbitrary web script or HTML via the _mbox parameter to the default URI.
Remediation
References
Related Vulnerabilities
WordPress Plugin Advanced Dynamic Pricing for WooCommerce Cross-Site Request Forgery (4.1.3)
WordPress Plugin Clio Grow Cross-Site Scripting (1.0)
OpenSSL Resource Management Errors Vulnerability (CVE-2014-3506)
WordPress Plugin All-in-One WP Migration Remote Code Execution (2.0.2)
Jenkins Permissions, Privileges, and Access Controls Vulnerability (CVE-2014-3663)