CVE-2020-12640

CRITICAL

Roundcube Webmail <1.4.4 - Path Traversal

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2020-12640. PoCs published by mbadanoiu.

AI-analyzed exploit summary This repository provides a writeup for CVE-2020-12640, a local PHP file inclusion vulnerability in Roundcube Webmail due to unsanitized plugin parameters. The vulnerability allows path traversal to include arbitrary PHP files, but no exploit code is provided.

Description

Roundcube Webmail before 1.4.4 allows attackers to include local files and execute code via directory traversal in a plugin name to rcube_plugin_api.php.

Exploits (1)

nomisec WRITEUP
by mbadanoiu · poc
https://github.com/mbadanoiu/CVE-2020-12640

This repository provides a writeup for CVE-2020-12640, a local PHP file inclusion vulnerability in Roundcube Webmail due to unsanitized plugin parameters. The vulnerability allows path traversal to include arbitrary PHP files, but no exploit code is provided.

Classification
Writeup 90%
Attack Type
Other
Complexity
Moderate
Reliability
Theoretical
Target: Roundcube Webmail before 1.4.4, 1.3.11, and 1.2.10
Auth required
Prerequisites: Access to the Roundcube Webmail installer component · Write access to the target's filesystem
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (7)

Core 7
Core References
Release Notes, Third Party Advisory x_refsource_misc
https://github.com/roundcube/roundcubemail/releases/tag/1.4.4
Release Notes, Third Party Advisory x_refsource_misc
https://github.com/roundcube/roundcubemail/compare/1.4.3...1.4.4
Third Party Advisory vendor-advisory x_refsource_gentoo
https://security.gentoo.org/glsa/202007-41
Third Party Advisory vendor-advisory x_refsource_suse
http://lists.opensuse.org/opensuse-security-announce/2020-09/msg00083.html

Scores

CVSS v3 9.8
EPSS 0.0673
EPSS Percentile 93.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-22
Status published
Products (4)
opensuse/backports_sle 15.0 sp1 (2 CPE variants)
opensuse/leap 15.1
opensuse/leap 15.2
roundcube/webmail 1.2.0 - 1.2.10
Published May 04, 2020
Tracked Since Feb 18, 2026