{"id":"CVE-2016-4068","details":"Cross-site scripting (XSS) vulnerability in Roundcube Webmail before 1.0.9 and 1.1.x before 1.1.5 allows remote attackers to inject arbitrary web script or HTML via a crafted SVG, a different vulnerability than CVE-2015-8864.","modified":"2026-08-03T11:45:22.107711661Z","published":"2017-04-13T14:59:01.713Z","database_specific":{"unresolved_ranges":[{"source":"CPE_RANGE","vendor_product":"roundcube:webmail","cpes":["cpe:2.3:a:roundcube:webmail:*:*:*:*:*:*:*:*"],"extracted_events":[{"last_affected":"1.0.8"}]},{"vendor_product":"opensuse:leap","cpes":["cpe:2.3:o:opensuse:leap:42.1:*:*:*:*:*:*:*"],"extracted_events":[{"introduced":"42.1"},{"last_affected":"42.1"}],"source":"CPE_STRING"},{"extracted_events":[{"introduced":"13.1"},{"last_affected":"13.1"},{"introduced":"13.2"},{"last_affected":"13.2"}],"source":"CPE_STRING","vendor_product":"opensuse:opensuse","cpes":["cpe:2.3:o:opensuse:opensuse:13.1:*:*:*:*:*:*:*","cpe:2.3:o:opensuse:opensuse:13.2:*:*:*:*:*:*:*"]},{"vendor_product":"roundcube:roundcube_webmail","cpes":["cpe:2.3:a:roundcube:roundcube_webmail:1.1.1:*:*:*:*:*:*:*","cpe:2.3:a:roundcube:roundcube_webmail:1.1.2:*:*:*:*:*:*:*","cpe:2.3:a:roundcube:roundcube_webmail:1.1.3:*:*:*:*:*:*:*"],"extracted_events":[{"introduced":"1.1.1"},{"last_affected":"1.1.1"},{"introduced":"1.1.2"},{"last_affected":"1.1.2"},{"introduced":"1.1.3"},{"last_affected":"1.1.3"}],"source":"CPE_STRING"},{"extracted_events":[{"introduced":"1.1"},{"last_affected":"1.1"},{"introduced":"1.1-beta"},{"last_affected":"1.1-beta"},{"introduced":"1.1-rc"},{"last_affected":"1.1-rc"},{"introduced":"1.1.4"},{"last_affected":"1.1.4"}],"source":"CPE_STRING","vendor_product":"roundcube:webmail","cpes":["cpe:2.3:a:roundcube:webmail:1.1.4:*:*:*:*:*:*:*","cpe:2.3:a:roundcube:webmail:1.1:*:*:*:*:*:*:*","cpe:2.3:a:roundcube:webmail:1.1:beta:*:*:*:*:*:*","cpe:2.3:a:roundcube:webmail:1.1:rc:*:*:*:*:*:*"]},{"extracted_events":[{"fixed":"1.0.9"},{"introduced":"1.1.x"},{"fixed":"1.1.5"}],"source":"DESCRIPTION"}]},"references":[{"type":"ADVISORY","url":"http://lists.opensuse.org/opensuse-updates/2016-08/msg00078.html"},{"type":"ADVISORY","url":"http://lists.opensuse.org/opensuse-updates/2016-08/msg00079.html"},{"type":"ADVISORY","url":"http://lists.opensuse.org/opensuse-updates/2016-08/msg00095.html"},{"type":"ADVISORY","url":"https://github.com/roundcube/roundcubemail/issues/4949"},{"type":"ADVISORY","url":"https://github.com/roundcube/roundcubemail/releases/tag/1.0.9"},{"type":"ADVISORY","url":"https://github.com/roundcube/roundcubemail/releases/tag/1.1.5"},{"type":"ADVISORY","url":"https://github.com/roundcube/roundcubemail/wiki/Changelog#release-115"},{"type":"FIX","url":"https://github.com/roundcube/roundcubemail/commit/40d7342dd9c9bd2a1d613edc848ed95a4d71aa18#commitcomment-15294218"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/roundcube/roundcubemail","events":[{"introduced":"0"},{"fixed":"40d7342dd9c9bd2a1d613edc848ed95a4d71aa18"},{"fixed":"cde7a9eb74b6fd6315885c30c0763e0ee5332499"},{"fixed":"25bc871ee79a6d469822d999b09c9b5d73fccf1f"}],"database_specific":{"source":"REFERENCES"}}],"versions":["1.0.8","1.1.4","1.2-beta","1.0.7","1.1.3","1.0.6","1.1.2","1.1.1","1.1.0","1.1-rc","1.0.5","1.0.4","1.1-beta","1.0.3","1.0.2","1.0.1","1.0.0","v1.0-rc","v0.1-beta2"],"database_specific":{"source":"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2016-4068.json"}}],"schema_version":"1.8.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"}]}