Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
In the rcfilters plugin 2.1.6 for Roundcube, XSS exists via the _whatfilter and _messages parameters (in the Filters section of the settings).
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Roundcube rcfilters插件跨站脚本漏洞
Vulnerability Description
rcfilters for Roundcube是一款使用在Roundcube邮件客户端中的过滤器插件。 Roundcube rcfilters插件2.1.6版本中的settings页面的Filters区域存在跨站脚本漏洞,该漏洞源于程序没有过滤用户的输入。远程攻击者可借助‘_whatfilter’和‘_messages’参数利用该漏洞在自己的账户过滤器列表中注入javascript和html代码。
CVSS Information
N/A
Vulnerability Type
N/A