Home / Vulnerabilities / CVE-2020-12641
CRITICAL SEVERITY
CVE-2020-12641 Roundcube · Roundcube Webmail

Roundcube Webmail Remote Code Execution Vulnerability

Technical Severity

CVSS v3.1 Metrics

CRITICAL
9.8 / 10
Minimal Risk Critical
Vector Specification
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitation Likelihood

EPSS Prediction

93.27 %
Predictive Probability
Percentile Rank
99.8 th

Documented as more likely to be exploited than 99.8% of known CVEs.

Detection Date

Jun 22, 2023

Remediation Due

Jul 13, 2023

CISA Catalog Active

Threat Analysis

Roundcube Webmail contains an remote code execution vulnerability that allows attackers to execute code via shell metacharacters in a configuration setting for im_convert_path or im_identify_path.

Remediation Directive

Apply updates per vendor instructions.

External Intelligence