Roundcube Webmail versions before 1.5.13 and 1.6.13 contained a vulnerability where the HTML sanitizer failed to block remote image loads through SVG feImage elements. While the sanitizer correctly blocked external resources on img, image, and use tags, it routed feImage href attributes through the wrong code path (wash_link

3m read time From nullcathedral.com
Post cover image
Table of contents
Vulnerability information #Background #Discovery #Technical details #Proof of concept #Impact #Remediation #Timeline #

Sort: