CVE-2020-12640
04.05.2020, 15:15
Roundcube Webmail before 1.4.4 allows attackers to include local files and execute code via directory traversal in a plugin name to rcube_plugin_api.php.
| Vendor | Product | Version |
|---|---|---|
| roundcube | webmail | 1.2.0 ≤ 𝑥 < 1.2.10 |
| roundcube | webmail | 1.3.0 ≤ 𝑥 < 1.3.11 |
| roundcube | webmail | 1.4.0 ≤ 𝑥 < 1.4.4 |
| opensuse | backports_sle | 15.0:sp1 |
| opensuse | backports_sle | 15.0:sp2 |
| opensuse | leap | 15.1 |
| opensuse | leap | 15.2 |
𝑥
= Vulnerable software versions
Debian Releases
Ubuntu Releases
Ubuntu Product | |||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| roundcube |
|
References