S4E just found a high top 10 tcp port service scan
critical·Product Based Web Vulnerabilities·Updated Jun 6, 2025

CVE-2025-49113 Scanner

CVE-2025-49113 Scanner - Remote Code Execution vulnerability in Roundcube Webmail

Est. Time~10 seconds
Scan TypeGroup Scan
Targetsdomain, subdomain, ipv4
CostFree
2.2k
Times Used
continuous scan runs
3.4k
Continuously Checked
assets under CS
23
Vulnerabilities Found
confirmed findings
References
🔴
CISA Known Exploited Vulnerability
This CVE is actively exploited in the wild. CISA mandates federal agencies to patch immediately.
CVECVE-2025-49113
8.8
CVSScritical
Exploitable remotely over the internet · low-privilege account sufficient.

Roundcube Webmail before 1.5.10 and 1.6.x before 1.6.11 allows remote code execution by authenticated users because the _from parameter in a URL is not validated in program/actions/settings/upload.php, leading to PHP Object Deserialization.

Attack Vector
Network
Privileges Req.
Low
User Interaction
None
Affected
Webmailby Roundcube
AFFECTED< 1.5.10SAFE ✓≥ 1.5.10
Updated Aug 22, 2026View on NVD →
Detail

Roundcube Webmail is a widely used webmail service provider accessed by millions around the globe. Known for its efficiency and user-friendliness, it is predominantly utilized by organizations and educational institutions to facilitate communication. The software can be hosted on a variety of platforms, enhancing its adaptability to different environments. It serves to provide a robust email management system allowing users to manage their mail, address books, and even calendar functions. Its open-source nature makes it a favorite among developers looking to customize their user interface. The software's capability to integrate various plugins increases its flexibility for personalized mailing experiences.

The scanned vulnerability is a Remote Code Execution (RCE) flaw prevalent in certain versions of the Roundcube Webmail. This exploit arises due to improper validation of the _from parameter in the settings upload action endpoint of the application. Authenticated users can perform PHP Object Deserialization which could further result in the execution of arbitrary code on the server. The affected versions include any editions prior to 1.5.10 and versions between 1.6.0 and 1.6.11, necessitating caution for systems running these iterations. This vulnerability poses a noteworthy risk given the criticality score attached to its occurrence. Mitigation would involve updating to the latest secure releases and employing security configurations that block unauthorized manipulations.

Remote Code Execution in Roundcube is facilitated via a vulnerability in the program/actions/settings/upload.php file, primarily affecting infernal and external operatives. In technical terms, this flaw is rooted in improper handling and validation of elements within user-uploaded parameters that could lead to object injection. The exploitation process involves authenticated users sending a crafted request to execute commands on the server under the guise of a legitimate transaction. Exploiters would generally manipulate the _from parameter to achieve unintended code execution. The template checks for certain variables such as rcversion and oast to ascertain if a system is vulnerable. Users validating these exploit attempts must ensure all communication with the server is monitored and audited.

Potential repercussions from this vulnerability, if left unaddressed, include unauthorized access to sensitive information stored on the server. Attackers exploiting this flaw might obtain control over the server system, leading to data breaches, unauthorized data manipulation, and service downtime. Moreover, the exploit can act as a conduit for further injections or serve as a foothold for launching more complex attack vectors. This could also involve network-wide compromises, leading to extensive damage across an organization's infrastructure. It is crucial to regularly update and run patches on webmail systems to mitigate potential threats.

REFERENCES

Solution Advice
  • Update Roundcube Webmail to version 1.5.10 or 1.6.11 or later.
  • Implement network-level filtering to monitor unusual traffic patterns to and from the application.
  • Regularly review and validate the system logs to detect unauthorized access attempts.
  • Employ host-based intrusion detection systems for early detection of exploitation attempts.
  • Conduct frequent security assessments and code reviews for any third-party plugins or extensions.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2025-49113 Scanner - Remote Code Execution vulnerability in Roundcube Webmail S4E