CVE-2023-43770 | Roundcube up to 1.4.13/1.5.3/1.6.2 Email rcube_string_replacer.php cross site scripting
A vulnerability classified as problematic has been found in Roundcube up to 1.4.13/1.5.3/1.6.2. This affects an unknown part in the library program/lib/Roundcube/rcube_string_replacer.php of the component Email Handler. The manipulation leads to cross site scripting.
This vulnerability is uniquely identified as CVE-2023-43770. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.