It was discovered that roundcube, a skinnable AJAX based webmail solution for IMAP servers, is prone to a cross-site scripting vulnerability via the animate tag in an SVG document and a information disclosure vulnerability in the HTML style sanitizer.
https://security-tracker.debian.org/tracker/DSA-6087-1
Continue reading...
https://security-tracker.debian.org/tracker/DSA-6087-1
Continue reading...

