Description
An issue was discovered in Roundcube Webmail before 1.3.12 and 1.4.x before 1.4.5. include/rcmail_output_html.php allows XSS via the username template object.
Remediation
References
Related Vulnerabilities
PHP Integer Overflow or Wraparound Vulnerability (CVE-2016-5096)
Plone CMS Weak Password Requirements Vulnerability (CVE-2020-7940)
WordPress Plugin Qyrr-simply and modern QR-Code creation Cross-Site Scripting (0.6)
WordPress Plugin Bilingual Linker Cross-Site Scripting (2.1.1)
Atlassian Jira Missing Authorization Vulnerability (CVE-2017-18101)