CVE Published: Invalid date format |
CVE Updated: 16/08/2024 |
CVE Year: 2024 Source: mitre |
Vendor: n/a |
Product: n/a Status : PUBLISHED
CVE-2024-37385 Description
Roundcube Webmail before 1.5.7 and 1.6.x before 1.6.7 on Windows allows command injection via im_convert_path and im_identify_path. NOTE: this issue exists because of an incomplete fix for CVE-2020-12641.