{"id":"CVE-2020-12640","details":"Roundcube Webmail before 1.4.4 allows attackers to include local files and execute code via directory traversal in a plugin name to rcube_plugin_api.php.","aliases":["BIT-roundcube-2020-12640"],"modified":"2026-09-11T03:45:06.335601089Z","published":"2020-05-04T15:15:14.357Z","related":["openSUSE-SU-2020:1516-1"],"database_specific":{"unresolved_ranges":[{"vendor_product":"opensuse:backports_sle","cpes":["cpe:2.3:a:opensuse:backports_sle:15.0:sp1:*:*:*:*:*:*","cpe:2.3:a:opensuse:backports_sle:15.0:sp2:*:*:*:*:*:*"],"extracted_events":[{"introduced":"15.0-sp1"},{"last_affected":"15.0-sp1"},{"introduced":"15.0-sp2"},{"last_affected":"15.0-sp2"}],"source":"CPE_STRING"},{"cpes":["cpe:2.3:o:opensuse:leap:15.1:*:*:*:*:*:*:*","cpe:2.3:o:opensuse:leap:15.2:*:*:*:*:*:*:*"],"extracted_events":[{"introduced":"15.1"},{"last_affected":"15.1"},{"introduced":"15.2"},{"last_affected":"15.2"}],"source":"CPE_STRING","vendor_product":"opensuse:leap"}]},"references":[{"type":"ADVISORY","url":"http://lists.opensuse.org/opensuse-security-announce/2020-09/msg00083.html"},{"type":"ADVISORY","url":"https://github.com/roundcube/roundcubemail/compare/1.4.3...1.4.4"},{"type":"ADVISORY","url":"https://github.com/roundcube/roundcubemail/releases/tag/1.4.4"},{"type":"ADVISORY","url":"https://roundcube.net/news/2020/04/29/security-updates-1.4.4-1.3.11-and-1.2.10"},{"type":"ADVISORY","url":"https://security.gentoo.org/glsa/202007-41"},{"type":"FIX","url":"https://github.com/roundcube/roundcubemail/commit/814eadb699e8576ce3a78f21e95bf69a7c7b3794"},{"type":"EVIDENCE","url":"https://github.com/DrunkenShells/Disclosures/tree/master/CVE-2020-12640-PHP%20Local%20File%20Inclusion-Roundcube"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/roundcube/roundcubemail","events":[{"introduced":"3198dedb585502faad472e6479cafc354e74d549"},{"fixed":"bda6421aab62b33c85158e5d8f2abd33915cf0c8"},{"introduced":"854aa7f35f6ed963033e2c0c4735852af7eca21b"},{"fixed":"fc0034d8375e470d51e77594c34545f6273cdd38"},{"introduced":"9291b74675e83c04d5365e010ba5186e672732fb"},{"fixed":"e449013ada51ccd539ca098d84dc7340356eb475"},{"fixed":"814eadb699e8576ce3a78f21e95bf69a7c7b3794"},{"fixed":"aadb13e25f73d783f731a99f9b9c2ea43bb10c79"}],"database_specific":{"source":["CPE_RANGE","REFERENCES"],"cpe":"cpe:2.3:a:roundcube:webmail:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"1.2.0"},{"fixed":"1.2.10"},{"introduced":"1.3.0"},{"fixed":"1.3.11"},{"introduced":"1.4.0"},{"fixed":"1.4.4"}]}}],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2020-12640.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"}]}