
CVE-2025-49113 - Roundcube <= 1.6.10 认证后远程代码执行漏洞(通过PHP对象反序列化)

CVE 编号: CVE-2025-49113
严重性: 严重 (CVSS 10.0)
发现者: Kirill Firsov (FearsOff)
披露日期: 2025年6月1日
修复版本: Roundcube 1.6.11 / 1.5.10 LTS
- https://nvd.nist.gov/vuln/detail/CVE-2025-49113
- https://github.com/advisories/GHSA-8j8w-wwqc-x596
- https://fearsoff.org/research/roundcube
- http://www.openwall.com/lists/oss-security/2025/06/02/3
- https://roundcube.net/news/2025/06/01/security-updates-1.6.11-and-1.5.10