Vulnerability record · CVE-2020-13965 · published 9 June 2020
CVE-2020-13965: Roundcube Webmail XSS via malicious XML attachment preview
Roundcube · Webmail
Roundcube Webmail before 1.3.12 and 1.4.x before 1.4.5 allows cross-site scripting because text/xml is among the allowed types for attachment preview. A crafted XML attachment can execute script in the webmail origin when previewed, which matters because webmail sessions hold mail content and credentials.
Description
An issue was discovered in Roundcube Webmail before 1.3.12 and 1.4.x before 1.4.5. There is XSS via a malicious XML attachment because text/xml is among the allowed types for a preview.
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Automated analysis
high priorityIt is in CISA KEV with a very high EPSS score and public exploit references, though the CVSS base score is medium and exploitation requires user interaction.
What it is
Roundcube Webmail before 1.3.12 and 1.4.x before 1.4.5 allows cross-site scripting because text/xml is among the allowed types for attachment preview. A crafted XML attachment can execute script in the webmail origin when previewed, which matters because webmail sessions hold mail content and credentials.
Impact
An attacker can run script in the victim's Roundcube session, enabling theft of session data or mail content and actions performed as the logged-in user. The CVSS vector scores scope change with low confidentiality and integrity impact.
Attack surface
Reached remotely over the network by sending an email with a malicious XML attachment that the victim previews; no authentication is needed to deliver the message, but user interaction is required to trigger the preview.
Exploitation
CISA added this to the Known Exploited Vulnerabilities catalog on 2024-06-26, and EPSS gives a 30-day probability of 0.76596 (99.5th percentile); public exploit references are tagged Exploit.
What to do
- Upgrade Roundcube Webmail to 1.3.12 or 1.4.5 or later; apply the vendor patch commit.
- Apply distribution updates for Debian and Fedora packages carrying Roundcube.
- If patching is not possible, disable or restrict attachment preview for text/xml and similar active content types.
- Follow CISA KEV required action: apply vendor mitigations or discontinue use of the product if mitigations are unavailable.
Detection
- Search mail gateway and webmail logs for XML attachments (text/xml, application/xml) delivered to Roundcube users.
- Monitor for unexpected script execution or anomalous requests originating from the webmail origin in browser or proxy telemetry.
- Review Roundcube version inventory to identify hosts below 1.3.12 or 1.4.5.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2020-13965 to the Known Exploited Vulnerabilities catalog on 26 June 2024 as "Roundcube Webmail Cross-Site Scripting (XSS) Vulnerability". Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Federal deadline 17 July 2024.
Affected products
3 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2020-13965 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2020-13965), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.