Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-53483 | Cross-Site Scripting (XSS) vulnerability in Roundcube Webmail 1.6.9 allows remote authenticated users to upload a malicious file as an email attachment, leading to the triggering of the XSS by visiting the SENT session. |
Mon, 22 Dec 2025 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Roundcube
Roundcube webmail |
|
| CPEs | cpe:2.3:a:roundcube:webmail:1.6.9:*:*:*:*:*:*:* | |
| Vendors & Products |
Roundcube
Roundcube webmail |
Mon, 14 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Wed, 12 Feb 2025 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-80 | |
| Metrics |
cvssV3_1
|
Mon, 03 Feb 2025 19:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Cross-Site Scripting (XSS) vulnerability in Roundcube Webmail 1.6.9 allows remote authenticated users to upload a malicious file as an email attachment, leading to the triggering of the XSS by visiting the SENT session. | |
| References |
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2025-02-12T19:18:08.984Z
Reserved: 2025-01-09T00:00:00.000Z
Link: CVE-2024-57004
Updated: 2025-02-05T16:14:01.847Z
Status : Analyzed
Published: 2025-02-03T19:15:12.777
Modified: 2025-12-22T16:03:05.057
Link: CVE-2024-57004
No data.
OpenCVE Enrichment
No data.
EUVD