CVE-2020-12641
Known Exploited (CISA KEV)CRITICAL
9.8
CVSS Severity Score
Vulnerability Description
rcube_image.php in Roundcube Webmail before 1.4.4 allows attackers to execute arbitrary code via shell metacharacters in a configuration setting for im_convert_path or im_identify_path.
Affected Platforms (CPE)
π¦
Roundcube
Webmail
>= 1.2.0 and < 1.2.10π¦
Roundcube
Webmail
>= 1.3.0 and < 1.3.11π¦
Roundcube
Webmail
>= 1.4.0 and < 1.4.4π¦
Opensuse
Backports Sle
= 15.0π¦
Opensuse
Backports Sle
= 15.0π»
Opensuse
Leap
= 15.1π»
Opensuse
