|
Bugzilla – Bug 1216895 |
VUL-0: CVE-2023-47272: Roundcube 1.5.x before 1.5.6 and 1.6.x before 1.6.5 allows XSS via a Content-Type or Content-Disposition header (used for attachment preview or download). |
Last modified: 2023-11-06 17:25:02 UTC |