Description
An issue was discovered in Roundcube Webmail before 1.3.12 and 1.4.x before 1.4.5. There is XSS via a malicious XML attachment because text/xml is among the allowed types for a preview.
Remediation
References
Related Vulnerabilities
Django Improper Input Validation Vulnerability (CVE-2012-4520)
IBM WebSEAL Improper Certificate Validation Vulnerability (CVE-2019-4150)
Drupal Core 7.x Multiple Vulnerabilities (7.0 - 7.51)
WordPress Plugin Users Ultra Membership Multiple Vulnerabilities (1.5.62)
WordPress Plugin WP Customize Login Cross-Site Scripting (1.1)