CVE-2025-49113: RCE in Roundcube Webmail, 9.9 rating 🔥
A vulnerability in Roundcube allows attackers to perform RCE due to the lack of validation of the _from parameter, which leads to PHP objects deserialization.
Search at Netlas.io:
👉 Link: https://nt.ls/9M4Rh
👉 Dork: http.headers.set_cookie:"roundcube_sessid"
Read more: https://fearsoff.org/research/roundcube
Post #412
1.26K

- 👾 3
- 🔥 2