VDB
Sign up
CRITICAL9.9

GHSA-8j8w-wwqc-x596

Roundcube Webmail Vulnerable to Authenticated RCE via PHP Object Deserialization

Quick fix

GHSA-8j8w-wwqc-x596 — roundcube/roundcubemail: upgrade to the fixed version with the command below.

composer require roundcube/roundcubemail:^1.5.10

Details

Roundcube Webmail before 1.5.10 and 1.6.x before 1.6.11 allows remote code execution by authenticated users because the _from parameter in a URL is not validated in program/actions/settings/upload.php, leading to PHP Object Deserialization.

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist/roundcube/roundcubemail
Introduced in: 0Fixed in: 1.5.10
Fixcomposer require roundcube/roundcubemail:^1.5.10
Packagist/roundcube/roundcubemail
Introduced in: 1.6.0Fixed in: 1.6.11
Fixcomposer require roundcube/roundcubemail:^1.6.11

References