Roundcube Webmail versions before 1.5.13 and 1.6.13 contained a vulnerability where the HTML sanitizer failed to block remote image loads through SVG feImage elements. While the sanitizer correctly blocked external resources on img, image, and use tags, it routed feImage href attributes through the wrong code path (wash_link
Table of contents
Vulnerability information #Background #Discovery #Technical details #Proof of concept #Impact #Remediation #Timeline #Sort: