CVE-2020-12641
Known Exploited (CISA KEV)CRITICAL
9.8
CVSS Severity Score
Vulnerability Description
rcube_image.php in Roundcube Webmail before 1.4.4 allows attackers to execute arbitrary code via shell metacharacters in a configuration setting for im_convert_path or im_identify_path.
Affected Platforms (CPE)
📦
Roundcube
Webmail
>= 1.2.0 and < 1.2.10📦
Roundcube
Webmail
>= 1.3.0 and < 1.3.11📦
Roundcube
Webmail
>= 1.4.0 and < 1.4.4📦
Opensuse
Backports Sle
= 15.0📦
Opensuse
Backports Sle
= 15.0💻
Opensuse
Leap
= 15.1💻
Opensuse
