Description
Roundcube before 1.3.17 and 1.4.x before 1.4.12 is prone to XSS in handling an attachment's filename extension when displaying a MIME type warning message.
Remediation
References
Related Vulnerabilities
WordPress Plugin Wechat Reward Cross-Site Request Forgery (1.7)
OpenSSL Numeric Errors Vulnerability (CVE-2012-2131)
Moodle Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2015-3176)
MySQL CVE-2024-20996 Vulnerability (CVE-2024-20996)
OpenSSL Resource Management Errors Vulnerability (CVE-2010-2939)