It was discovered that roundcube, a skinnable AJAX based webmail solution for IMAP servers, did not properly sanitize HTML messages. This would allow an attacker to load arbitrary JavaScript code.
https://security-tracker.debian.org/tracker/DSA-5531-1
Continue reading...
https://security-tracker.debian.org/tracker/DSA-5531-1
Continue reading...