Description
Roundcube Webmail before 1.3.15 and 1.4.8 allows stored XSS in HTML messages during message display via a crafted SVG document. This issue has been fixed in 1.4.8 and 1.3.15.
Remediation
References
Related Vulnerabilities
Drupal Core 8.x.x Information Disclosure (8.0.0 - 8.7.14)
Drupal CVE-2007-0626 Vulnerability (CVE-2007-0626)
WordPress Plugin Woocommerce Product Designer Arbitrary File Upload (3.0.3)
WordPress Plugin Passster-Password Protection Weak Encoding (3.5.5.5.1)
WordPress Plugin FV Flowplayer Video Player Multiple Vulnerabilities (7.3.14.727)