rcube_image.php in Roundcube Webmail before 1.4.4 allows...
High severity
Unreviewed
Published
May 24, 2022
to the GitHub Advisory Database
•
Updated Jan 29, 2023
Description
Published by the National Vulnerability Database
May 4, 2020
Published to the GitHub Advisory Database
May 24, 2022
Last updated
Jan 29, 2023
rcube_image.php in Roundcube Webmail before 1.4.4 allows attackers to execute arbitrary code via shell metacharacters in a configuration setting for im_convert_path or im_identify_path.
References