CVE-2025-49113 | Roundcube Webmail up to 1.5.9/1.6.10 upload.php _from deserialization (EUVD-2025-16605 / EDB-52324)
A vulnerability classified as critical was found in Roundcube Webmail up to 1.5.9/1.6.10. This vulnerability affects unknown code of the file program/actions/settings/upload.php. Executing manipulation of the argument _from can lead to deserialization.
This vulnerability is handled as CVE-2025-49113. The attack can be executed remotely. Additionally, an exploit exists.
Upgrading the affected component is advised.