CVE-2020-12641
Act now ● On CISA KEV — actively exploited
Actively exploited — on the CISA KEV list.
CVSS base
—
EPSS — probability of exploitation (30 days)
84.3%
99.7th percentile
CISA KEV
Listed
Added 2023-06-22 · patch by 2023-07-13
Weakness / dates
—
Published — · modified —
Description
Roundcube Webmail contains an remote code execution vulnerability that allows attackers to execute code via shell metacharacters in a configuration setting for im_convert_path or im_identify_path.