Description
Roundcube Webmail before 1.3.15 and 1.4.8 allows stored XSS in HTML messages during message display via a crafted SVG document. This issue has been fixed in 1.4.8 and 1.3.15.
Remediation
References
Related Vulnerabilities
WordPress 4.2.x Cross-Site Scripting Vulnerability (4.2 - 4.2.5)
Drupal Core 4.5.x Cross-Site Scripting (4.5.0 - 4.5.1)
WordPress Plugin Login Widget With Shortcode Cross-Site Request Forgery (3.1.1)
TYPO3 Cryptographic Issues Vulnerability (CVE-2012-3527)
WordPress Plugin Instagram Feed Cross-Site Scripting (1.5.1)