AVG-2891 log
| Package | roundcubemail |
| Status | Fixed |
| Severity | Critical |
| Type | arbitrary code execution |
| Affected | 1.6.10-1 |
| Fixed | 1.6.11-1 |
| Current | 1.6.11-1 [extra] |
| Ticket | None |
| Created | Tue Jun 3 00:50:16 2025 |
| Issue | Severity | Remote | Type | Description |
|---|---|---|---|---|
| CVE-2025-49113 | Critical | Yes | Arbitrary code execution | Roundcube Webmail before 1.5.10 and 1.6.x before 1.6.11 allows remote code execution by authenticated users because the _from parameter in a URL is not... |
| Date | Advisory | Package | Type |
|---|---|---|---|
| 04 Jun 2025 | ASA-202506-1 | roundcubemail | arbitrary code execution |