Vulnerability record · CVE-2020-35730 · published 28 December 2020
CVE-2020-35730: Roundcube Webmail stored XSS via link reference handling
Roundcube · Webmail
Roundcube Webmail mishandles JavaScript inside a link reference element in plain text email, allowing script injection through linkref_addindex in rcube_string_replacer.php. The flaw affects versions before 1.2.13, 1.3.x before 1.3.16, and 1.4.x before 1.4.10. Because webmail is a high-value, browser-facing target, successful exploitation can compromise the mail session of any user who views the crafted message.
Description
An XSS issue was discovered in Roundcube Webmail before 1.2.13, 1.3.x before 1.3.16, and 1.4.x before 1.4.10. The attacker can send a plain text e-mail message, with JavaScript in a link reference element that is mishandled by linkref_addindex in rcube_string_replacer.php.
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Automated analysis
high priorityThe flaw is remotely reachable with low complexity, is listed in CISA KEV with a high EPSS score, and targets a widely deployed webmail application, though it requires user interaction and has only medium CVSS severity.
What it is
Roundcube Webmail mishandles JavaScript inside a link reference element in plain text email, allowing script injection through linkref_addindex in rcube_string_replacer.php. The flaw affects versions before 1.2.13, 1.3.x before 1.3.16, and 1.4.x before 1.4.10. Because webmail is a high-value, browser-facing target, successful exploitation can compromise the mail session of any user who views the crafted message.
Impact
An attacker can execute arbitrary JavaScript in the victim's webmail origin, enabling theft of session cookies or credentials, reading of mailbox contents, and actions performed as the victim.
Attack surface
Reached remotely over the network by sending a crafted plain text email to the target; no authentication is required to deliver the message, but the victim must open or view it (UI:R). The CVSS vector is AV:N/AC:L/PR:N/UI:R/S:C.
Exploitation
CVE-2020-35730 is listed in CISA KEV (added 2023-06-22, due 2023-07-13) and has an EPSS 30-day probability of 0.32688 (98.255 percentile), indicating active exploitation in the wild. No ransomware campaign use is documented.
What to do
- Upgrade Roundcube Webmail to 1.2.13, 1.3.16, 1.4.10 or later, or apply the vendor patch referenced in the 1.4.9 to 1.4.10 comparison.
- Update distribution packages on Fedora and Debian to the fixed versions announced in the vendor mailing lists.
- Enforce a strict Content-Security-Policy on the webmail origin to limit script execution impact.
- Restrict or disable automatic rendering of remote content and links in email where operationally feasible.
- Monitor vendor advisories and re-check exposure if older Roundcube branches remain deployed.
Detection
- Search webmail and proxy logs for requests containing suspicious JavaScript or link reference patterns in message rendering paths.
- Hunt for anomalous outbound requests or session cookie exfiltration from the webmail host following email viewing.
- Review mail gateway logs for inbound plain text messages with unusual link reference elements targeting Roundcube users.
- Correlate webmail access logs with known exploitation indicators and alert on unexpected script-like payloads in message bodies.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2020-35730 to the Known Exploited Vulnerabilities catalog on 22 June 2023 as "Roundcube Webmail Cross-Site Scripting (XSS) Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 13 July 2023.
Affected products
3 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2020-35730 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2020-35730), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.