Description
Cross-site scripting (XSS) vulnerability in program/include/rcmail.php in Roundcube Webmail 1.1.x before 1.1.2 allows remote attackers to inject arbitrary web script or HTML via the _mbox parameter to the default URI.
Remediation
References
Related Vulnerabilities
WordPress Plugin WP Background Takeover Directory Traversal (4.1.4)
MySQL CVE-2016-0608 Vulnerability (CVE-2016-0608)
Mailman Improper Restriction of Excessive Authentication Attempts Vulnerability (CVE-2021-42096)
MediaWiki Improper Restriction of Excessive Authentication Attempts Vulnerability (CVE-2020-25827)
WordPress Plugin Clean Login Cross-Site Scripting (1.12.6.3)