CVE-2020-12640
9.8
CRITICAL · CVSS 3.1 · EPSS 6.7% (pctl 94)
In your normal cycle
Critical by CVSS (9.8), but no sign of active exploitation.
Description
Roundcube Webmail before 1.4.4 allows attackers to include local files and execute code via directory traversal in a plugin name to rcube_plugin_api.php.
Scoring
| CVSS | 9.8 (CRITICAL, v3.1) |
|---|---|
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| EPSS | 6.73% — more likely to be exploited than 94% of all CVEs |
| Weakness | CWE-22 |
| On CISA KEV | no |
| Public exploit | none known |
| Published | 2020-05-04 |
| Last modified | 2026-06-17 |
Affected (3)
| Vendor | Product |
|---|---|
| opensuse | backports sle |
| opensuse | leap |
| roundcube | webmail |
References
- http://lists.opensuse.org/opensuse-security-announce/2020-09/msg00083.html
- https://github.com/DrunkenShells/Disclosures/tree/master/CVE-2020-12640-PHP%20Local%20File%20Inclusion-Roundcube
- https://github.com/roundcube/roundcubemail/commit/814eadb699e8576ce3a78f21e95bf69a7c7b3794
- https://github.com/roundcube/roundcubemail/compare/1.4.3...1.4.4
- https://github.com/roundcube/roundcubemail/releases/tag/1.4.4
- https://roundcube.net/news/2020/04/29/security-updates-1.4.4-1.3.11-and-1.2.10
- https://security.gentoo.org/glsa/202007-41
- http://lists.opensuse.org/opensuse-security-announce/2020-09/msg00083.html
- https://github.com/DrunkenShells/Disclosures/tree/master/CVE-2020-12640-PHP%20Local%20File%20Inclusion-Roundcube
- https://github.com/roundcube/roundcubemail/commit/814eadb699e8576ce3a78f21e95bf69a7c7b3794
- https://github.com/roundcube/roundcubemail/compare/1.4.3...1.4.4
- https://github.com/roundcube/roundcubemail/releases/tag/1.4.4
- https://roundcube.net/news/2020/04/29/security-updates-1.4.4-1.3.11-and-1.2.10
- https://security.gentoo.org/glsa/202007-41
→ the Explorer · watch your stack · NVD