Cross-site scripting (XSS) vulnerability in program/steps...
Low severity
Unreviewed
Published
May 17, 2022
to the GitHub Advisory Database
•
Updated Apr 11, 2025
Description
Published by the National Vulnerability Database
Aug 25, 2012
Published to the GitHub Advisory Database
May 17, 2022
Last updated
Apr 11, 2025
Cross-site scripting (XSS) vulnerability in program/steps/mail/func.inc in RoundCube Webmail before 0.8.0, when using the Larry skin, allows remote attackers to inject arbitrary web script or HTML via the email message subject.
References