Roundcube before 1.4.13 and 1.5.x before 1.5.2 allows XSS via an HTML e-mail message with crafted Cascading Style Sheets (CSS) token sequences.
| Software | From | Fixed in |
|---|---|---|
| roundcube / roundcube | 1.5.0 | 1.5.2 |
| roundcube / roundcube | - | 1.4.13 |
| debian / debian_linux | 9.0 | 9.0.x |
| debian / debian_linux | 10.0 | 10.0.x |
| debian / debian_linux | 11.0 | 11.0.x |