CVE-2013-1904: Roundcube Webmail
Medium severity, CVSS 5.0. EPSS: 2.3% chance of exploitation in the next 30 days.
Absolute path traversal vulnerability in steps/mail/sendmail.inc in Roundcube Webmail before 0.7.3 and 0.8.x before 0.8.6 allows remote attackers to read arbitrary files via a full pathname in the _value parameter for the generic_message_footer setting in a save-perf action to index.php, as exploited in the wild in March 2013.
Affected products
- Roundcube Webmail: up to and including 0.7.2; version 0.1 only; version 0.1.1 only; version 0.2 only; version 0.2.1 only; version 0.2.2 only; …
Published 2014-02-08. Last modified 2026-06-16.