Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-48844

Опубликовано: 25 мая 2026
Источник: nvd
CVSS3: 7.5
EPSS Низкий

Описание

Roundcube Webmail 1.6.x before 1.6.16 and 1.7.x before 1.7.1 has insecure code evaluation logic in LDAP the autovalues option that could lead to code injection. (Support for code evaluation has been removed in 1.6.16 and 1.7.1.)

EPSS

Процентиль: 34%
0.00414
Низкий

7.5 High

CVSS3

Дефекты

CWE-670

Связанные уязвимости

CVSS3: 7.5
ubuntu
2 месяца назад

Roundcube Webmail 1.6.x before 1.6.16 and 1.7.x before 1.7.1 has insecure code evaluation logic in LDAP the autovalues option that could lead to code injection. (Support for code evaluation has been removed in 1.6.16 and 1.7.1.)

CVSS3: 7.5
debian
2 месяца назад

Roundcube Webmail 1.6.x before 1.6.16 and 1.7.x before 1.7.1 has insec ...

CVSS3: 7.5
github
2 месяца назад

Roundcube Webmail 1.6.x before 1.6.16 and 1.7.x before 1.7.1 has insecure code evaluation logic in LDAP the autovalues option that could lead to code injection. (Support for code evaluation has been removed in 1.6.16 and 1.7.1.)

CVSS3: 7.5
fstec
3 месяца назад

Уязвимость реализации протокола LDAP почтового клиента RoundCube Webmail, позволяющая нарушителю выполнить произвольный код

suse-cvrf
2 месяца назад

Security update for roundcubemail

EPSS

Процентиль: 34%
0.00414
Низкий

7.5 High

CVSS3

Дефекты

CWE-670