github roundcube/roundcubemail 1.2.11
Roundcube Webmail 1.2.11

latest releases: 1.6.6, 1.4.16, 1.6.5...
3 years ago

This is a security update to the LTS version 1.2.
It fixes a recently reported cross-site scripting (XSS) vulnerability via HTML messages with malicious svg/namespace (CVE-2020-15562).

Credits for this finding go to SSD Secure Disclosure.

We strongly recommend to update all productive installations of Roundcube 1.2.x
if you cannot upgrade to a more recent version. Please do backup your data before updating!

Don't miss a new roundcubemail release

NewReleases is sending notifications on new releases.