Looking for the vulnerability index of Invicti's legacy products?
Roundcube Deserialization of Untrusted Data Vulnerability - CVE-2025-49113 - Vulnerability Database

Roundcube Deserialization of Untrusted Data Vulnerability - CVE-2025-49113

High
Reference: CVE-2025-49113
Title: Roundcube Deserialization of Untrusted Data Vulnerability
Overview:

Roundcube Webmail before 1.5.10 and 1.6.x before 1.6.11 allows remote code execution by authenticated users because the _from parameter in a URL is not validated in program/actions/settings/upload.php leading to PHP Object Deserialization.