EXPOSURES › CVE-2020-12641
CVE-2020-12641
HIGH ⌖ ON CISA KEV · EXPLOITEDRoundcube Webmail Remote Code Execution Vulnerability exposed in 84,000 servers
An actively exploited remote code execution vulnerability in Roundcube Webmail allows attackers to execute arbitrary code. This poses a significant risk to over 84,000 servers, impacting network security and data integrity. DIB organizations should ensure their systems are patched and monitored for this vulnerability.
Shame score — The vulnerability was actively exploited, affecting a large number of servers and posing a significant risk to network security.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Roundcube Webmail contains an remote code execution vulnerability that allows attackers to execute code via shell metacharacters in a configuration setting for im_convert_path or im_identify_path.