CVE-2024-37383
Act now ● On CISA KEV — actively exploited
Actively exploited — on the CISA KEV list.
CVSS base
—
EPSS — probability of exploitation (30 days)
73.3%
99.4th percentile
CISA KEV
Listed
Added 2024-10-24 · patch by 2024-11-14
Weakness / dates
—
Published — · modified —
Description
RoundCube Webmail contains a cross-site scripting (XSS) vulnerability in the handling of SVG animate attributes that allows a remote attacker to run malicious JavaScript code.