https://seclists.org/oss-sec/2025/q2/189: Roundcube webmail: Post-Auth RCE via PHP Object Deserialization ported by firs0v
Published Jun 2, 2025
·Updated
Affected Software
1 affected component
Roundcube Roundcube Webmail=1.5.10, =1.6.11
Frequently Asked Questions
1
What is the severity of Roundcube webmail: Post-Auth RCE via PHP Object Deserialization?
The severity of Roundcube webmail: Post-Auth RCE via PHP Object Deserialization is considered high due to the potential for remote code execution.
2
How do I fix Roundcube webmail: Post-Auth RCE via PHP Object Deserialization?
To fix Roundcube webmail: Post-Auth RCE via PHP Object Deserialization, update to the latest versions 1.6.11 or 1.5.10 as released by Roundcube.
3
What is the impact of Roundcube webmail: Post-Auth RCE via PHP Object Deserialization?
The impact of Roundcube webmail: Post-Auth RCE via PHP Object Deserialization is significant, allowing attackers to execute malicious code after user authentication.
4
When was the Roundcube webmail: Post-Auth RCE via PHP Object Deserialization vulnerability published?
The Roundcube webmail: Post-Auth RCE via PHP Object Deserialization vulnerability was published on June 2, 2025.
5
Who reported the Roundcube webmail: Post-Auth RCE via PHP Object Deserialization vulnerability?
The Roundcube webmail: Post-Auth RCE via PHP Object Deserialization vulnerability was reported by a security researcher known as firs0v.