This is a heavily interactive web application, and JavaScript is required. Simple HTML interfaces are possible, but that is not what this is.
Post
The Shadowserver Foundation
shadowserver.bsky.social
did:plc:3xyh2kw5hfxsax4zff3pp5ub
We have started scanning & reporting Roundcube Webmail servers vulnerable to CVE-2023-5631. While rated "only" CVSS 5.4, it has been used by at least one APT actor to execute JavaScript code in the browser of the victim in context of their Roundcube session. 42K vulnerable!
2023-10-28T19:21:36.062Z