Roundcube Webmail before 1.4.4 contains a command injection caused by shell metacharacters in configuration settings for im_convert_path or im_identify_path, letting attackers execute arbitrary code, exploit requires attacker to control configuration settings.
id: CVE-2020-12641
info:
name: Roundcube Webmail - Command Injection
author: domwhewell-sage
...