Junglewise Threat Intelligence

CVE-2020-12641: Roundcube Webmail Remote Code Execution Vulnerability

CVE-2020-12641 · Severity: critical · CVSS 9.8 · Exploited in the wild · Published 2023-06-22

Technologies: Roundcube Webmail. Vendors: Roundcube.

Executive brief

rcube_image.php in Roundcube Webmail before 1.4.4 allows remote attackers to execute arbitrary code via shell metacharacters in the im_convert_path or im_identify_path configuration settings. This command injection vulnerability stems from improper neutralization of special elements used in an OS command.

Affected products

  • Roundcube Webmail before 1.4.4

Timeline

  • 2020-04-29: patched: Vendor released security updates 1.4.4, 1.3.11, and 1.2.10
  • 2023-06-22: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
  • 2023-06-22: disclosed: NVD publication date

Related threats