CVE-2020-12640: Path Traversal
Roundcube Webmail before 1.4.4 allows attackers to include local files and execute code via directory traversal in a plugin name to rcubepluginapi.php.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2020-12640?
CVE-2020-12640 is a vulnerability in Roundcube Webmail that allows attackers to include local files and execute code via directory traversal in a plugin name to rcube_plugin_api.php.
How severe is CVE-2020-12640?
CVE-2020-12640 has a severity rating of 9.8 (Critical).
Which versions of Roundcube Webmail are affected by CVE-2020-12640?
Roundcube Webmail versions 1.2.0 to 1.2.10, 1.3.0 to 1.3.11, and 1.4.0 to 1.4.4 are affected by CVE-2020-12640.
How can an attacker exploit CVE-2020-12640?
An attacker can exploit CVE-2020-12640 by using directory traversal in a plugin name to rcube_plugin_api.php and including local files to execute arbitrary code.
Are there any references for CVE-2020-12640?
Yes, you can find references for CVE-2020-12640 at the following links: - http://lists.opensuse.org/opensuse-security-announce/2020-09/msg00083.html - https://github.com/DrunkenShells/Disclosures/tree/master/CVE-2020-12640-PHP%20Local%20File%20Inclusion-Roundcube - https://github.com/roundcube/roundcubemail/commit/814eadb699e8576ce3a78f21e95bf69a7c7b3794