CVE-2025-49113
Roundcube · Published June 2, 2025
9.9
CVSS v3.1
CRITICALCISA KEV — Federal agencies must patch by deadline
Actively exploited in the wild
Patch availableGet patch
Description
Roundcube Webmail before 1.5.10 and 1.6.x before 1.6.11 allows remote code execution by authenticated users because the _from parameter in a URL is not validated in program/actions/settings/upload.php, leading to PHP Object Deserialization.
Affected Products
- Webmail < 1.5.10
- Webmail < 1.6.11
- Debian Linux
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H