← Back to browse · API

CVE-2024-37383

Severity
MEDIUM
CVSS
6.1
EPSS
0.73296
Risk score
75.05
CISA KEV
Yes
PoC
No
Published
2024-10-24
Modified
2024-10-24
First seen
2026-08-07
Aliases
EUVD-2024-36625, GHSA-8J3W-26MP-75XH
Products
Roundcube:Webmail, n/a:n/a n/a
Sources
euvd EUVD-2024-36625
cisa.gov CVE-2024-37383

Description

RoundCube Webmail contains a cross-site scripting (XSS) vulnerability in the handling of SVG animate attributes that allows a remote attacker to run malicious JavaScript code.

References