CyberSec.Space Logo
Back to CVE Browser

CVE-2020-12641

Known Exploited (CISA KEV)CRITICAL
9.8
CVSS Severity Score
EPSS Score51.2550%
EPSS Percentile97.39th
PublishedMay 4, 2020
Last ModifiedNov 4, 2025

Vulnerability Description

rcube_image.php in Roundcube Webmail before 1.4.4 allows attackers to execute arbitrary code via shell metacharacters in a configuration setting for im_convert_path or im_identify_path.

Affected Platforms (CPE)

πŸ“¦
Roundcube

Webmail

>= 1.2.0 and < 1.2.10
πŸ“¦
Roundcube

Webmail

>= 1.3.0 and < 1.3.11
πŸ“¦
Roundcube

Webmail

>= 1.4.0 and < 1.4.4
πŸ“¦
Opensuse

Backports Sle

= 15.0
πŸ“¦
Opensuse

Backports Sle

= 15.0
πŸ’»
Opensuse

Leap

= 15.1
πŸ’»
Opensuse

Leap

= 15.2

References & Advisories

Related Vulnerabilities