CVE-2020-12641

roundcube webmail, opensuse backports sle, opensuse leap

Published 4 May 2020 · updated 17 Jun 2026 · Analyzed

9.8 Critical · CVSS 3.1, NVD

Exploited in the wild

CISA added this to its Known Exploited Vulnerabilities catalog on 22 Jun 2023, with a remediation deadline of 13 Jul 2023 for US federal agencies.

Required action: Apply updates per vendor instructions.

Description

rcube_image.php in Roundcube Webmail before 1.4.4 allows attackers to execute arbitrary code via shell metacharacters in a configuration setting for im_convert_path or im_identify_path.

References