Home
MEDIUM: 4.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:NDefault status
unaffected
Any version before 1.5.13
affected
1.6.0 (semver) before 1.6.13
affected
Description
Roundcube Webmail before 1.5.13 and 1.6 before 1.6.13, when "Block remote images" is used, does not block SVG feImage.
Problem types
CWE-420 Unprotected Alternate Channel
Product status
Any version before 1.5.13
1.6.0 (semver) before 1.6.13
References
nullcathedral.com/...ndcube-svg-feimage-remote-image-bypass/
github.com/roundcube/roundcubemail/commit/26d7677
news.ycombinator.com/item?id=46937012