Executive brief
rcube_image.php in Roundcube Webmail before 1.4.4 allows remote attackers to execute arbitrary code via shell metacharacters in the im_convert_path or im_identify_path configuration settings. This command injection vulnerability stems from improper neutralization of special elements used in an OS command.
Affected products
- Roundcube Webmail before 1.4.4
Timeline
- 2020-04-29: patched: Vendor released security updates 1.4.4, 1.3.11, and 1.2.10
- 2023-06-22: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
- 2023-06-22: disclosed: NVD publication date