Retour à la veille

CVE-2026-75000

Publié : 17 août 2026
Modifié : 17 août 2026
Lien officiel NVD
Score CVSS
5.8
MEDIUM

Description détaillée

In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, improper HTML/CSS sanitization of the SVG animate "by" attribute may lead to remote image blocking bypass, which in turn may lead to information disclosure or privilege escalation.

Vecteur d'attaque (CVSS)

Vecteur brut :CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:N

Références et Patchs