A vulnerability classified as problematic was found in Roundcube up to 1.6.16/1.7.1. Affected by this vulnerability is an unknown functionality of the component TNEF decoder. The manipulation results in cross site scripting. The attack may be performed from remote.
| Vendor | Product | Versions |
|---|---|---|
| roundcube | webmail | 1.6.0, 1.7.0, 1.6.16, 1.7.1 |
Updated description with new details, changed severity to HIGH, and modified affected versions to include 1.6.16 and 1.7.1.
Initial creation