CVE-2020-12641 | RoundCube Webmail up to 1.4.3 Config Setting rcube_image.php Shell Metacharacter argument injection
A vulnerability has been found in RoundCube Webmail up to 1.4.3 and classified as critical. Affected by this vulnerability is an unknown functionality of the file rcube_image.php of the component Config Setting Handler. The manipulation as part of Shell Metacharacter leads to argument injection.
This vulnerability is known as CVE-2020-12641. The attack can be launched remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.