← Back to browse · API

CVE-2023-43770

Severity
MEDIUM
CVSS
6.1
EPSS
0.58483
Risk score
69.87
CISA KEV
Yes
PoC
No
Published
2023-09-22
Modified
2025-10-21
First seen
2026-08-07
Aliases
EUVD-2023-48147, GHSA-G3FV-4F2H-XWV4
Products
Roundcube:Webmail, n/a:n/a n/a
Sources
cisa.gov CVE-2023-43770
euvd EUVD-2023-48147

Description

Roundcube before 1.4.14, 1.5.x before 1.5.4, and 1.6.x before 1.6.3 allows XSS via text/plain e-mail messages with crafted links because of program/lib/Roundcube/rcube_string_replacer.php behavior.

References