The US Cybersecurity and Infrastructure Security Agency (CISA) has announced a moderate severity security flaw affecting the Roundcube email software.

vulnerability - site scripting (XSS) flaw caused by the inadequate handling of report links in plain text messages.
See more: CISA: Adds Chrome vulnerability to KEV List
According to CISA, Roundcube Webmail has a cross-site scripting (XSS) vulnerability that can reveal information through malicious redirects in plain text messages.
According to a bug description in NIST's National Vulnerability Database (NVD), the vulnerability affects Roundcube versions before version 1.4.14, 1.5.x versions before version 1.5.4, and 1.6.x versions before version 1.6.3.
The flaw was addressed by Roundcube maintainers with version 1.6.3, which was released on September 15, 2023. Zscaler security researcher Niraj Shivtarkar appears to have discovered and reported the vulnerability.
Although the nature of the vulnerability has not yet been clarified, the web- email have been exploited by Russia-related threat actors such as APT28 and Winter Vivern.

Read also: New vulnerabilities in Cisco, Fortinet, VMware require immediate updates
The US Federal Civilian Executive Branch (FCEB) has mandated the implementation of patches offered by their vendor by March 4, 2024, in order to protect its networks from potential threats.
Source: thehackernews.com
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
