CRITICAL

CVE-2020-12640

CVSS v3

9.8

CRITICAL

EPSS Score

22.7%

exploit probability

CISA KEV

No

known exploited

Exploitation

SSVC status

Description

Roundcube Webmail before 1.4.4 allows attackers to include local files and execute code via directory traversal in a plugin name to rcube_plugin_api.php.

Technical details

Published
5/4/2020

Frequently asked questions

What is CVE-2020-12640?

Roundcube Webmail before 1.4.4 allows attackers to include local files and execute code via directory traversal in a plugin name to rcube_plugin_api.php.

Is CVE-2020-12640 actively exploited?

Active exploitation of CVE-2020-12640 has not been confirmed. The EPSS score is 22.7%, indicating the estimated probability of exploitation in the next 30 days.

What is the CVSS score for CVE-2020-12640?

CVE-2020-12640 has a CVSS v3 base score of 9.8 (CRITICAL severity).

Is CVE-2020-12640 affecting your environment?

Use isMalicious to check if any of your IPs or domains are associated with this vulnerability's IOCs.