CVE-2020-12641
Roundcube Roundcube Webmail
rcube_image.php in Roundcube Webmail before 1.4.4 allows attackers to execute arbitrary code via shell metacharacters in a configuration setting for im_convert_path or im_identify_path.
- CVSS
- 9.8
- EPSS
- 84.5% 99.7% percentile
- CISA KEV
- Listed
- Published
- 2020.05.05