newstrooper newstrooper
  • Home
  • World News
  • Politics
  • Sports
  • Entertainment
  • Business
  • Technology
  • Travel
  • Gaming
Reading: Important 10-year-old round cube webmail bug allows authenticated users to execute malicious code
Share

News Trooper

Your Global Insight, Delivered Daily.

Search
  • Home
  • World News
  • Politics
  • Sports
  • Entertainment
  • Business
  • Technology
  • Travel
  • Gaming
Follow US
© 2025 All Rights Reserved | Powered by News Trooper News
News Trooper > Technology > Important 10-year-old round cube webmail bug allows authenticated users to execute malicious code
Technology

Important 10-year-old round cube webmail bug allows authenticated users to execute malicious code

June 3, 2025 2 Min Read
Share
Important 10-year-old round cube webmail bug allows authenticated users to execute malicious code
SHARE

Cybersecurity researchers unnoticed for 10 years, uncovered, have revealed details of critical security flaws in RoundCube Webmail software that can be exploited to carry over the sensitivity system and execute arbitrary code.

Tracked vulnerabilities CVE-2025-49113carry a CVSS score of 9.9 out of 10.0. This is described as an example of prominent remote code execution via the descent of PHP objects.

“The round cube webmail before 1.5.10 and 1.6.x before 1.5.10 and 1.6.x allows remote code execution by authenticated users as the URL’s _FROM parameter is not verified in program/action/settings/upload.php, leading to deregistration of PHP objects,” reads a flaw description in Nist’s National Vulnerability Database (NVD).

The drawbacks that affect all versions of software, including 1.6.10, are addressed in 1.6.11 and 1.5.10 LTS. Kirill Firsov, founder and CEO of Fearsoff, is acknowledged to have discovered and reported the defect.

The Dubai-based cybersecurity company has simply recommended that it intends to “soon” the published technical details and “POCs) to give users plenty of time to apply the necessary patches.

https://www.youtube.com/watch?v=tbktbmjwhjy

The previously disclosed security vulnerabilities in the Round Cube were the favourable targets of nation-state threat actors such as APT28 and Winter Vivern. Last year, Positive Technology revealed that it attempted to exploit a flaw in the Round Cube (CVE-2024-37383) as part of a phishing attack designed to steal user credentials.

Then, a few weeks ago, ESET noted that APT28 exploited cross-site scripting (XSS) vulnerabilities on various webmail servers such as RoundCube, Horde, Mdaemon, and Zimbra to collect sensitive data from specific email accounts belonging to government entities and defense companies in Eastern Europe.

See also  How to stop the AI ​​drawing of iPhone in a past era

Share This Article
Facebook Twitter Copy Link
Previous Article No rematch has yet to be released, and already has 1.9 million players. No rematch has yet to be released, and already has 1.9 million players.
Next Article New research uses attachment theory to decipher relationships with humans New research uses attachment theory to decipher relationships with humans
Leave a comment Leave a comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular News

Musk’s decision to limit political spending leaves some Republicans cold

Musk’s decision to limit political spending leaves some Republicans cold

Elon Musk's pledge to retreat from campaign spending -- if…

June 2, 2025
GOP Rep. Bill Huizenga is preparing to run for Michigan's open Senate seat

GOP Rep. Bill Huizenga is preparing to run for Michigan's open Senate seat

McKinnack Island, Mich. -- Republican Rep. Bill Huizenga is preparing…

June 2, 2025
'It betrays our values': Progressives grapple with deadly shooting

'It betrays our values': Progressives grapple with deadly shooting

Progressive is tackling that two people who worked at the…

June 2, 2025
Beshear, Khanna to headline Dem mayor summit in July

Beshear, Khanna to headline Dem mayor summit in July

Two potential 2028 presidential primary candidates will descend on Cleveland…

June 2, 2025
Democrats are ‘stuck in that unfortunate reality’ in debate over Biden's illness

Democrats are ‘stuck in that unfortunate reality’ in debate over Biden's illness

24 hours after Sunday's announcement that former President Joe Biden…

June 2, 2025

You Might Also Like

New research uses attachment theory to decipher relationships with humans
Technology

New research uses attachment theory to decipher relationships with humans

9 Min Read
Understand Helpdesk fraud and how to protect your organization
Technology

Understand Helpdesk fraud and how to protect your organization

13 Min Read
How Manus AI is redefineing autonomous workflow automation across the industry
Technology

How Manus AI is redefineing autonomous workflow automation across the industry

11 Min Read
Cryptojacking campaign explores the DevOps API using ready-made tools from GitHub
Technology

Cryptojacking campaign explores the DevOps API using ready-made tools from GitHub

6 Min Read
newstrooper
newstrooper

Welcome to News Trooper, your reliable destination for global news that matters. In an age of information overload, we stand as a dedicated news platform committed to delivering timely, accurate, and insightful coverage of the world’s most significant events and trends.

  • Business
  • Entertainment
  • Gaming
  • Politics
  • Sports
  • Technology
  • Travel
  • World News
  • About us
  • Contact Us
  • Disclaimer
  • Privacy Policy
  • Terms of Service
  • Home
  • World News
  • Politics
  • Sports
  • Entertainment
  • Business
  • Technology
  • Travel
  • Gaming
  • About us
  • Contact Us
  • Disclaimer
  • Privacy Policy
  • Terms of Service

© 2025 All Rights Reserved | Powered by News Trooper News

Welcome Back!

Sign in to your account

Lost your password?