CVE-2020-12640
04.05.2020, 15:15
Roundcube Webmail before 1.4.4 allows attackers to include local files and execute code via directory traversal in a plugin name to rcube_plugin_api.php.
Vendor | Product | Version |
---|---|---|
roundcube | webmail | 1.2.0 ≤ 𝑥 < 1.2.10 |
roundcube | webmail | 1.3.0 ≤ 𝑥 < 1.3.11 |
roundcube | webmail | 1.4.0 ≤ 𝑥 < 1.4.4 |
opensuse | backports_sle | 15.0:sp1 |
opensuse | backports_sle | 15.0:sp2 |
opensuse | leap | 15.1 |
opensuse | leap | 15.2 |
𝑥
= Vulnerable software versions

Debian Releases

Ubuntu Releases
Ubuntu Product | |||||||||||||||||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
roundcube |
|
References