Impact
A vulnerability in the markasjunk plugin’s cmd_learn driver allows an attacker to execute arbitrary system commands on a Roundcube Webmail server. The flaw is triggered when a crafted placeholder replacement value is processed, leading to an OS command injection. The impact is full remote code execution, potentially compromising confidentiality, integrity, and availability of affected systems.
Affected Systems
The flaw affects Roundcube Webmail installations that use the markasjunk plugin with the cmd_learn driver. Versions before 1.6.18 and before 1.7.3 are vulnerable. All other Roundcube versions and installations not using this plugin are not affected.
Risk and Exploitability
The vulnerability has a CVSS score of 8.8, signifying high severity. Exploitation requires the ability to submit crafted placeholder replacement data to the plugin, which is likely achievable via a web request to the affected server. The EPSS score is not available and the issue is not listed in CISA’s KEV catalog, but the lack of a public exploit does not diminish the potential risk. The attack vector is presumably remote, and successful exploitation could give an attacker full control over the affected webmail host.
OpenCVE Enrichment
Debian DLA
Debian DSA