mod_css_styles in Roundcube through 1.5.7 and 1.6.x through 1.6.7 insufficiently filters Cascading Style Sheets (CSS) token sequences in rendered e-mail messages, allowing a remote attacker to obtain sensitive information.
CVSS Details
- CVSS 3.1 Base Score: 7.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade roundcube | Aug 9, 2024 | Aug 5, 2024 |
| Freebsd | — | Upgrade roundcube | Aug 10, 2024 | Aug 10, 2024 |
| Suse | — | Upgrade roundcubemail | Dec 5, 2025 | Oct 9, 2024 |
| Ubuntu | — | Upgrade roundcube-plugins (Ubuntu Pro)Upgrade roundcube-core (Ubuntu Pro) | Apr 29, 2026 | Aug 5, 2024 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub