{"id":"CVE-2016-4068","details":"Cross-site scripting (XSS) vulnerability in Roundcube Webmail before 1.0.9 and 1.1.x before 1.1.5 allows remote attackers to inject arbitrary web script or HTML via a crafted SVG, a different vulnerability than CVE-2015-8864.","modified":"2026-08-07T11:47:25.609753219Z","published":"2017-04-13T14:59:01.713Z","database_specific":{"unresolved_ranges":[{"extracted_events":[{"introduced":"42.1"},{"last_affected":"42.1"}],"source":"CPE_STRING","vendor_product":"opensuse:leap","cpes":["cpe:2.3:o:opensuse:leap:42.1:*:*:*:*:*:*:*"]},{"source":"CPE_STRING","vendor_product":"opensuse:opensuse","cpes":["cpe:2.3:o:opensuse:opensuse:13.1:*:*:*:*:*:*:*","cpe:2.3:o:opensuse:opensuse:13.2:*:*:*:*:*:*:*"],"extracted_events":[{"introduced":"13.1"},{"last_affected":"13.1"},{"introduced":"13.2"},{"last_affected":"13.2"}]},{"source":"CPE_STRING","vendor_product":"roundcube:roundcube_webmail","cpes":["cpe:2.3:a:roundcube:roundcube_webmail:1.1.1:*:*:*:*:*:*:*","cpe:2.3:a:roundcube:roundcube_webmail:1.1.2:*:*:*:*:*:*:*","cpe:2.3:a:roundcube:roundcube_webmail:1.1.3:*:*:*:*:*:*:*"],"extracted_events":[{"introduced":"1.1.1"},{"last_affected":"1.1.1"},{"introduced":"1.1.2"},{"last_affected":"1.1.2"},{"introduced":"1.1.3"},{"last_affected":"1.1.3"}]}]},"references":[{"type":"ADVISORY","url":"http://lists.opensuse.org/opensuse-updates/2016-08/msg00078.html"},{"type":"ADVISORY","url":"http://lists.opensuse.org/opensuse-updates/2016-08/msg00079.html"},{"type":"ADVISORY","url":"http://lists.opensuse.org/opensuse-updates/2016-08/msg00095.html"},{"type":"ADVISORY","url":"https://github.com/roundcube/roundcubemail/issues/4949"},{"type":"ADVISORY","url":"https://github.com/roundcube/roundcubemail/releases/tag/1.0.9"},{"type":"ADVISORY","url":"https://github.com/roundcube/roundcubemail/releases/tag/1.1.5"},{"type":"ADVISORY","url":"https://github.com/roundcube/roundcubemail/wiki/Changelog#release-115"},{"type":"FIX","url":"https://github.com/roundcube/roundcubemail/commit/40d7342dd9c9bd2a1d613edc848ed95a4d71aa18#commitcomment-15294218"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/roundcube/roundcubemail","events":[{"introduced":"0"},{"last_affected":"2c0a550105f22e17307198bb295f83c210fb7cb5"},{"introduced":"190ae4f800b2d40c0edb579b34c1b188089c2a6a"},{"last_affected":"772e08fa2a7211e68aa6179811cf82ac124c9bf2"},{"fixed":"40d7342dd9c9bd2a1d613edc848ed95a4d71aa18"},{"fixed":"cde7a9eb74b6fd6315885c30c0763e0ee5332499"},{"fixed":"25bc871ee79a6d469822d999b09c9b5d73fccf1f"}],"database_specific":{"source":["CPE_RANGE","CPE_STRING","REFERENCES"],"cpe":["cpe:2.3:a:roundcube:webmail:*:*:*:*:*:*:*:*","cpe:2.3:a:roundcube:webmail:1.1:*:*:*:*:*:*:*","cpe:2.3:a:roundcube:webmail:1.1:beta:*:*:*:*:*:*","cpe:2.3:a:roundcube:webmail:1.1:rc:*:*:*:*:*:*","cpe:2.3:a:roundcube:webmail:1.1.4:*:*:*:*:*:*:*"],"extracted_events":[{"introduced":"0"},{"last_affected":"1.0.8"},{"introduced":"1.1"},{"last_affected":"1.1"},{"introduced":"1.1-beta"},{"last_affected":"1.1-beta"},{"introduced":"1.1-rc"},{"last_affected":"1.1-rc"},{"introduced":"1.1.4"},{"last_affected":"1.1.4"}]}}],"versions":["1.1","1.1-beta","1.1-rc","1.1.4","1.0.8","1.2-beta","1.0.7","1.1.3","1.0.6","1.1.2","1.1.1","1.1.0","1.0.5","1.0.4","1.0.3","1.0.2","1.0.1","1.0.0","v1.0-rc","v0.1-beta2"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2016-4068.json"}}],"schema_version":"1.8.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"}]}