CVE-2024-37383
KEVMEDIUM 6.1EPSS 73.3%
Roundcube Webmail before 1.5.7 and 1.6.x before 1.6.7 allows XSS via SVG animate attributes.
- CVSS v3.1
- 6.1 MEDIUM
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N - CVSS v3.1
- 6.1 MEDIUM
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N - EPSS
- 73.30% chance of exploitation in the next 30 days, 99th percentile
- CISA KEV
- added 2024-10-24
- Published
- 2024-06-07
- Updated
- 2025-10-21
Proof-of-concept exploits (3)
- amirzargham/CVE-2024-37383-exploit0★ · 2024-12-07
- bartfroklage/CVE-2024-37383-POC5★ · 2024-10-24
- hyungin0505/CVE-2024-37383_PoC