Description
rcube_utils.php in Roundcube before 1.1.8 and 1.2.x before 1.2.4 is susceptible to a cross-site scripting vulnerability via a crafted Cascading Style Sheets (CSS) token sequence within an SVG element.
Remediation
References
Related Vulnerabilities
WordPress Plugin N-Media Website Contact Form with File Upload Arbitrary File Upload (1.3.4)
WordPress Plugin SS Downloads Multiple Cross-Site Scripting Vulnerabilities (1.4.4.1)
WordPress Plugin Product Addons & Fields for WooCommerce Same Origin Method Execution (SOME) (14.0)
Internet Information Services CVE-2009-4444 Vulnerability (CVE-2009-4444)