Another XSS in roundcube


I just stumbled over this announcement by the roundcube project. There is another XSS vulnerability that can be triggered by just opening modified mails.

Thankfully I and my users don’t use roundcube and I wish I could disable it for good in my installation. I’d rather write sieve scripts by hand and put them in place, than to have this huge target around.


added: I just found the PR in github. A big thank you to the committer

1 Like

Thank you to @kiekerjan to raising it in slack with the version and hash :blush:

1 Like