{"cveID":"CVE-2023-43770","vendorProject":"Roundcube","product":"Webmail","vulnerabilityName":"Roundcube Webmail Persistent Cross-Site Scripting (XSS) Vulnerability","dateAdded":"2024-02-12","shortDescription":"Roundcube Webmail contains a persistent cross-site scripting (XSS) vulnerability that can lead to information disclosure via malicious link references in plain/text messages.","requiredAction":"Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.","dueDate":"2024-03-04","knownRansomwareCampaignUse":"Unknown","notes":"https://roundcube.net/news/2023/09/15/security-update-1.6.3-released ;  https://nvd.nist.gov/vuln/detail/CVE-2023-43770","cwes":["CWE-79"],"year":2023,"state":"mapped","stale_reasons":[],"mappings":[{"domain":"enterprise","cve":"CVE-2023-43770","technique":"T1189","technique_name_at_mapping":"Drive-by Compromise","mapping_type":"exploitation_technique","capability_group":"xss","comments":"This vulnerability is exploited by an adversary via malicious links embedded in trustworthy websites to infiltrate victim systems. Successful exploitation grants the adversary the ability to execute arbitrary code on the impacted system. \n\nThe Russia-aligned hacking group TAG-70 has been attributed to exploiting this vulnerability. TAG-70 has used this vulnerability in an espionage campaign targeting European government and military agencies, as well as Iranian embassies in Russia, aiming to gather intelligence on European political and military activities. The campaign, active from early to mid-October 2023, is part of a broader pattern of Russian state-aligned cyber-espionage targeting email services.","references":["https://hivepro.com/wp-content/uploads/2024/02/Roundcube-Webmail-Faces-Unrelenting-Exploitation_TA2024073.pdf?utm_sr=google&utm_cmd=organic&utm_ccn=(not%20set)&utm_ctr=(not%20provided)","https://therecord.media/russia-aligned-hackers-target-european-and-iranian-embassies-cyber-espionage"],"status":"complete","source_file":"kev-07.28.2025_attack-16.1-enterprise.json","attack_version":"16.1","kev_snapshot":"07/28/2025"},{"domain":"enterprise","cve":"CVE-2023-43770","technique":"T1059","technique_name_at_mapping":"Command and Scripting Interpreter","mapping_type":"primary_impact","capability_group":"xss","comments":"This vulnerability is exploited by an adversary via malicious links embedded in trustworthy websites to infiltrate victim systems. Successful exploitation grants the adversary the ability to execute arbitrary code on the impacted system. \n\nThe Russia-aligned hacking group TAG-70 has been attributed to exploiting this vulnerability. TAG-70 has used this vulnerability in an espionage campaign targeting European government and military agencies, as well as Iranian embassies in Russia, aiming to gather intelligence on European political and military activities. The campaign, active from early to mid-October 2023, is part of a broader pattern of Russian state-aligned cyber-espionage targeting email services.","references":["https://therecord.media/russia-aligned-hackers-target-european-and-iranian-embassies-cyber-espionage"],"status":"complete","source_file":"kev-07.28.2025_attack-16.1-enterprise.json","attack_version":"16.1","kev_snapshot":"07/28/2025"},{"domain":"enterprise","cve":"CVE-2023-43770","technique":"T1082","technique_name_at_mapping":"System Information Discovery","mapping_type":"secondary_impact","capability_group":"xss","comments":"This vulnerability is exploited by an adversary via malicious links embedded in trustworthy websites to infiltrate victim systems. Successful exploitation grants the adversary the ability to execute arbitrary code on the impacted system. \n\nThe Russia-aligned hacking group TAG-70 has been attributed to exploiting this vulnerability. TAG-70 has used this vulnerability in an espionage campaign targeting European government and military agencies, as well as Iranian embassies in Russia, aiming to gather intelligence on European political and military activities. The campaign, active from early to mid-October 2023, is part of a broader pattern of Russian state-aligned cyber-espionage targeting email services.","references":["https://therecord.media/russia-aligned-hackers-target-european-and-iranian-embassies-cyber-espionage"],"status":"complete","source_file":"kev-07.28.2025_attack-16.1-enterprise.json","attack_version":"16.1","kev_snapshot":"07/28/2025"}],"techniques":[{"id":"T1059","domains":["enterprise"],"in_current_bundle":true,"live":true,"name_now":"Command and Scripting Interpreter","name_at_mapping":"Command and Scripting Interpreter","renamed":false,"revoked_by":null,"mapping_types":["primary_impact"],"sigma_rule_count":95,"has_detection_strategy":true},{"id":"T1082","domains":["enterprise"],"in_current_bundle":true,"live":true,"name_now":"System Information Discovery","name_at_mapping":"System Information Discovery","renamed":false,"revoked_by":null,"mapping_types":["secondary_impact"],"sigma_rule_count":33,"has_detection_strategy":true},{"id":"T1189","domains":["enterprise"],"in_current_bundle":true,"live":true,"name_now":"Drive-by Compromise","name_at_mapping":"Drive-by Compromise","renamed":false,"revoked_by":null,"mapping_types":["exploitation_technique"],"sigma_rule_count":3,"has_detection_strategy":true}],"mapping_types":["exploitation_technique","primary_impact","secondary_impact"],"has_exploitation_technique":true,"mapping_attack_versions":["16.1"],"mapping_domains":["enterprise"],"sigma_coverage":"full","sigma_rules_tagged_cve":[],"added_after_mapping_snapshot":false,"_source":"kevmap","_built":"2026-08-24 19:45 UTC","_attack_version":"19.2"}