XSS vulnerabilities when saving HTML signatures and when editing a message "as new" or draft in roundcubemail before 0.9.3 (CVE-2013-5645).
{ "section": "core" }