目标达成 感谢每一位支持者 — 我们达成了 100% 目标!

目标: 1000 元 · 已筹: 1359 元

100%

CVE-2025-49113 PoC — Roundcube Webmail 安全漏洞

来源
关联漏洞
标题: Roundcube Webmail 安全漏洞 (CVE-2025-49113)
Description:Roundcube Webmail是Roundcube开源的一款基于浏览器的开源IMAP客户端,它支持地址薄管理、信息搜索、拼写检查等。 Roundcube Webmail 1.5.10之前版本和 1.6.11之前版本存在安全漏洞,该漏洞源于未验证_from参数,可能导致PHP对象反序列化攻击。
Description
Detection for CVE-2025-49113
介绍
# CVE-2025-49113 Detection

**NOTE**
This template has now been implemented into CERT Polska's tool Artemis. I’m deeply honoured to be acknowledged by CERT Polska for this vulnerability detection script. It is a true privilege to play a part in strengthening global cyber security efforts through open-source contributions. 
https://github.com/CERT-Polska/Artemis/pull/1762

 ## How does this detection method work?

This template looks at the HTML body for the `rcversion` value and then matches on vulnerable versions. Here is a mapping of the RAW HTML value and version mapping for Roundcube:
```
10502	1.5.2
10601	1.6.1
10506	1.5.6
10500	1.5.0
10609	1.6.9
10611	1.6.11
10510	1.5.10
10505	1.5.5
10503	1.5.3
10610	1.6.10
10509	1.5.9
10607	1.6.7
10602	1.6.2
10606	1.6.6
10605	1.6.5
```

![image](https://github.com/user-attachments/assets/99f7736a-fc80-43fb-864f-14210638705d)

**This is not an exploit script but rather a script to detect whether an instance is vulnerable to CVE-2025-49113 based on versions.**

 ## How do I run this script?

1. Download Nuclei from [here](https://github.com/projectdiscovery/nuclei)
2. Copy the template to your local system
3. Run the following command: `nuclei -u https://yourHost.com -t template.yaml` 

## References

- https://thehackernews.com/2025/06/critical-10-year-old-roundcube-webmail.html
- https://access.redhat.com/security/cve/cve-2025-49113


## Disclaimer

Use at your own risk, I will not be responsible for illegal activities you conduct on infrastructure you do not own or have permission to scan.

## Contact

Feel free to reach out to me on [Signal](https://signal.me/#eu/0Qd68U1ivXNdWCF4hf70UYFo7tB0w-GQqFpYcyV6-yr4exn2SclB6bFeP7wTAxQw).
文件快照

登录后查看神龙缓存的 POC 文件快照

登录查看
备注
    1. 建议优先通过来源进行访问。
    2. 本地 POC 快照面向订阅用户开放;当原始来源失效或无法访问时,本地镜像作为订阅权益的一部分提供。
    3. 持续抓取、验证、维护这份 POC 档案需要不少投入,因此本地快照已纳入付费订阅。您的订阅是让这份资料能继续走下去的关键,由衷感谢。 查看订阅方案 →