Web1 vuln-feed

Finding #2

Inventory item php-test 8.3.31 (software, php)
TitleRoundcube Webmail: RoundCube Webmail Deserialization of Untrusted Data Vulnerability
Matchkeyword / confidence low
Statusnew
First seen2026-06-11T07:35:11Z
Last updated2026-06-11T07:35:11Z
Source advisoryRoundcube Webmail: RoundCube Webmail Deserialization of Untrusted Data Vulnerability
RoundCube Webmail contains a deserialization of untrusted data vulnerability that allows remote code execution by authenticated users because the _from parameter in a URL is not validated in program/actions/settings/upload.php.

Update status