CVE-2025-49113 | Teknoloji dünyasından en güncel haberleri ve güvenlikle ilgili gelişmeleri takip edin.

Roundcube Webmail before 1.5.10 and 1.6.x before 1.6.11 allows remote code execution by authenticated users because the _from parameter in a URL is not validate…
Critical KEV CVSS: 9.9

CVE-2025-49113

Roundcube Webmail before 1.5.10 and 1.6.x before 1.6.11 allows remote code execution by authenticated users because the _from parameter in a URL is not validated in program/actions/settings/upload.php, leading to PHP Object Deserialization.
Vendor
Roundcube
Product
Webmail
CWE
CWE-502
Yayın Tarihi
2025-06-02 05:15:53
Güncelleme
2026-02-23 13:24:21
Source Identifier
cve@mitre.org
KEV Date Added
2026-02-20

Kategoriler

Referanslar