CVE-2018-16736 | rcfilters Plugin 2.1.6 on RoundCube _whatfilter/_messages cross site scripting (Issue 19 / EDB-45437)
A vulnerability classified as problematic has been found in rcfilters Plugin 2.1.6 on RoundCube. Affected is an unknown function. The manipulation of the argument _whatfilter/_messages as part of Parameter leads to cross site scripting.
This vulnerability is traded as CVE-2018-16736. It is possible to launch the attack remotely. Furthermore, there is an exploit available.