CVE-2025-49113 | Roundcube Webmail up to 1.5.9/1.6.10 upload.php _from deserialization
A vulnerability was found in Roundcube Webmail up to 1.5.9/1.6.10. It has been rated as critical. This issue affects some unknown processing of the file program/actions/settings/upload.php. The manipulation of the argument _from leads to deserialization.
The identification of this vulnerability is CVE-2025-49113. The attack may be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.