{"cveID":"CVE-2020-12641","vendorProject":"Roundcube","product":"Roundcube Webmail","vulnerabilityName":"Roundcube Webmail Remote Code Execution Vulnerability","dateAdded":"2023-06-22","shortDescription":"Roundcube Webmail contains an remote code execution vulnerability that allows attackers to execute code via shell metacharacters in a configuration setting for im_convert_path or im_identify_path.","requiredAction":"Apply updates per vendor instructions.","dueDate":"2023-07-13","knownRansomwareCampaignUse":"Unknown","notes":"https://roundcube.net/news/2020/04/29/security-updates-1.4.4-1.3.11-and-1.2.10; https://nvd.nist.gov/vuln/detail/CVE-2020-12641","cwes":["CWE-78"],"year":2020,"state":"unmapped","stale_reasons":[],"mappings":[],"techniques":[],"mapping_types":[],"has_exploitation_technique":false,"mapping_attack_versions":[],"mapping_domains":[],"sigma_coverage":null,"sigma_rules_tagged_cve":[],"added_after_mapping_snapshot":false,"_source":"kevmap","_built":"2026-08-23 05:47 UTC","_attack_version":"19.2"}