CVE-2024-37383 | Roundcube Webmail up to 1.5.6/1.6.6 SVG animate cross site scripting (EDB-52173)
A vulnerability was found in Roundcube Webmail up to 1.5.6/1.6.6. It has been classified as problematic. Affected is an unknown function of the component SVG Handler. The manipulation of the argument animate leads to cross site scripting.
This vulnerability is traded as CVE-2024-37383. It is possible to launch the attack remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.