{ "CVE_data_meta" : { "ASSIGNER" : "cve@mitre.org", "ID" : "CVE-2017-6820", "STATE" : "PUBLIC" }, "affects" : { "vendor" : { "vendor_data" : [ { "product" : { "product_data" : [ { "product_name" : "n/a", "version" : { "version_data" : [ { "version_value" : "n/a" } ] } } ] }, "vendor_name" : "n/a" } ] } }, "data_format" : "MITRE", "data_type" : "CVE", "data_version" : "4.0", "description" : { "description_data" : [ { "lang" : "eng", "value" : "rcube_utils.php in Roundcube before 1.1.8 and 1.2.x before 1.2.4 is susceptible to a cross-site scripting vulnerability via a crafted Cascading Style Sheets (CSS) token sequence within an SVG element." } ] }, "problemtype" : { "problemtype_data" : [ { "description" : [ { "lang" : "eng", "value" : "n/a" } ] } ] }, "references" : { "reference_data" : [ { "name" : "https://github.com/roundcube/roundcubemail/commit/cbd35626f7db7855f3b5e2db00d28ecc1554e9f4", "refsource" : "CONFIRM", "url" : "https://github.com/roundcube/roundcubemail/commit/cbd35626f7db7855f3b5e2db00d28ecc1554e9f4" }, { "name" : "https://github.com/roundcube/roundcubemail/commit/fa2824fdcd44af3f970b2797feb47652482c8305", "refsource" : "CONFIRM", "url" : "https://github.com/roundcube/roundcubemail/commit/fa2824fdcd44af3f970b2797feb47652482c8305" }, { "name" : "https://github.com/roundcube/roundcubemail/releases/tag/1.1.8", "refsource" : "CONFIRM", "url" : "https://github.com/roundcube/roundcubemail/releases/tag/1.1.8" }, { "name" : "https://github.com/roundcube/roundcubemail/releases/tag/1.2.4", "refsource" : "CONFIRM", "url" : "https://github.com/roundcube/roundcubemail/releases/tag/1.2.4" }, { "name" : "https://github.com/roundcube/roundcubemail/wiki/Changelog#release-124", "refsource" : "CONFIRM", "url" : "https://github.com/roundcube/roundcubemail/wiki/Changelog#release-124" }, { "name" : "https://roundcube.net/news/2017/03/10/updates-1.2.4-and-1.1.8-released", "refsource" : "CONFIRM", "url" : "https://roundcube.net/news/2017/03/10/updates-1.2.4-and-1.1.8-released" }, { "name" : "96817", "refsource" : "BID", "url" : "http://www.securityfocus.com/bid/96817" } ] } }