← Back to browse · API

CVE-2024-42010

Severity
HIGH
CVSS
7.5
EPSS
0.5281
Risk score
48.48
CISA KEV
No
PoC
No
Published
2024-08-05
Modified
2024-08-12
First seen
2026-08-07
Aliases
EUVD-2024-39392, GHSA-853R-XR2F-R2X6
Products
n/a:n/a n/a
Sources
euvd EUVD-2024-39392

Description

mod_css_styles in Roundcube through 1.5.7 and 1.6.x through 1.6.7 insufficiently filters Cascading Style Sheets (CSS) token sequences in rendered e-mail messages, allowing a remote attacker to obtain sensitive information.

References