Roundcube Webmail before 1.5.10 and 1.6.x before 1.6.11 allows remote code execution by authenticated users because the _from parameter in a URL is not validated in program/actions/settings/upload.php, leading to PHP Object Deserialization.
References
Configurations
History
No history.
Information
Published : 2025-06-02 05:15
Updated : 2025-12-22 18:00
NVD link : CVE-2025-49113
Mitre link : CVE-2025-49113
CVE.ORG link : CVE-2025-49113
JSON object : View
Products Affected
debian
- debian_linux
roundcube
- webmail
CWE
CWE-502
Deserialization of Untrusted Data
