AVG-2891 log

Package roundcubemail
Status Fixed
Severity Critical
Type arbitrary code execution
Affected 1.6.10-1
Fixed 1.6.11-1
Current 1.6.11-1 [extra]
Ticket None
Created Tue Jun 3 00:50:16 2025
Issue Severity Remote Type Description
CVE-2025-49113 Critical Yes Arbitrary code execution
Roundcube Webmail before 1.5.10 and 1.6.x before 1.6.11 allows remote code execution by authenticated users because the _from parameter in a URL is not...
Date Advisory Package Type
04 Jun 2025 ASA-202506-1 roundcubemail arbitrary code execution