We use these services and cookies to improve your user experience. You may opt out if you wish, however, this may limit some features on this site.
Please see our statement on Data Privacy.
Roundcube Webmail before 1.5.10 and 1.6.x before 1.6.11 allows remote code execution by authenticated users because the _from parameter in a URL is not validated in program/actions/settings/upload.php, leading to PHP Object Deserialization.
Reserved 2025-06-02 | Published 2025-06-02 | Updated 2025-06-02 | Assigner mitreCWE-502 Deserialization of Untrusted Data
roundcube.net/...25/06/01/security-updates-1.6.11-and-1.5.10
github.com/roundcube/roundcubemail/pull/9865
github.com/roundcube/roundcubemail/releases/tag/1.6.11
github.com/...ommit/0376f69e958a8fef7f6f09e352c541b4e7729c4d
github.com/roundcube/roundcubemail/releases/tag/1.5.10
github.com/...ommit/7408f31379666124a39f9cb1018f62bc5e2dc695
github.com/...ommit/c50a07d88ca38f018a0f4a0b008e9a1deb32637e
fearsoff.org/research/roundcube
Support options