Close Menu
Pineapples Update –Pineapples Update –

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    iOS 26 will help you screen your calls and messages for spam

    June 10, 2025

    Aptos’ APT profit 4%, more possible reverse on important quantity

    June 10, 2025

    SMBs are fretting about rising costs before a hard year

    June 10, 2025
    Facebook X (Twitter) Instagram
    Facebook X (Twitter) Instagram Pinterest Vimeo
    Pineapples Update –Pineapples Update –
    • Home
    • Gaming
    • Gadgets
    • Startups
    • Security
    • How-To
    • AI/ML
    • Apps
    • Web3
    Pineapples Update –Pineapples Update –
    Home»Security»More than 84,000 roundcube examples are actively unsafe for exploited defects
    Security

    More than 84,000 roundcube examples are actively unsafe for exploited defects

    PineapplesUpdateBy PineapplesUpdateJune 10, 2025No Comments2 Mins Read
    Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
    More than 84,000 roundcube examples are actively unsafe for exploited defects
    Share
    Facebook Twitter LinkedIn Pinterest Email

    More than 84,000 roundcube examples are actively unsafe for exploited defects

    More than 84,000 roundcube webmail installations are unsafe for CVE-2025-49113, a significant remote code execution (RCE) is a blame with a public exploitation.

    The defect, which affects the roundcube versions through 1.6.10 through 1.6.10, was over a decade. Patching on 1 June 2025After the discovery and reporting by safety researcher Kiril Ferresov.

    The bug is stems from $ $ _GET (‘_ to’) input, when the session keys compete when the sessions begin with a amazing sign mark, PHP Object Disorganization and Sessions are able to corruption.

    Shortly after the patch was released, hackers reverse-engineer to develop a working exploitation, which they sold on underground forums.

    Although exploitation Cve-2025-49113 The authentication requires, the attackers claim that legitimate credentials can be obtained through CSRF, log scraping, or cruel-maze.

    Firesov shared technical details about the defect On their blog To help protect against active exploitation efforts, which is likely to be too much.

    Large -scale risk

    Roundcube is widely used in widely shared hosting (Godaddy, hostinger, ovh) and widely used in government, education and technical sectors, with more than 1,200,000 examples online.

    Threatening monitoring platform Report of shadowseerver foundation That its internet scans return 84,925 rounds Weak to CVE-2025-49113 by 8 June 2025.

    Most of these examples are in the United States (19,500), India (15,500), Germany (13,600), France (3,600), Canada (3,500), and United Kingdom (2,400).

    Heartat
    Heartat
    Source: Shadowseerver Foundation

    Considering the high risk of exploitation and the ability of data theft, contact of those examples is an important cyber security risk.

    System administrators are recommended to update versions 1.6.11 and 1.5.10, which address the CVE-2025–49113 as soon as possible.

    It is not clear whether the defect is being done in real attacks and on which scale is being leveraged, but immediate action is recommended.

    If it is impossible to upgrade, it is recommended to restrict access to webmels, close the file uploads, add CSRF security, block risky PHP function and monitor for exploitation indicators.


    Tines needle

    Patching meant complex scripts, long and endless fire drills. No more.

    In this new guide, the tines break down how it is leveling with modern organ automation. Patch fast, reduce overhead, and focus on strategic tasks – no complex script is required.

    actively defects examples exploited roundcube unsafe
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    Previous ArticleWWDC 2025: All facilities for iOS 26 and Macos 26 Apple ‘Loan’
    Next Article The garden with apple walls is the largest road to the iPad to become Mac
    PineapplesUpdate
    • Website

    Related Posts

    Security

    Google Patch bug leak phone number tied to accounts

    June 10, 2025
    Security

    Dangerous truth about ‘non -Nonlathal’ weapons used against LA protesters

    June 10, 2025
    Security

    Stolen tickets from snowflake attacks briefly for sale

    June 9, 2025
    Add A Comment
    Leave A Reply Cancel Reply

    Top Posts

    Microsoft’s new text editor is a VIM and Nano option

    May 19, 2025656 Views

    The best luxury car for buyers for the first time in 2025

    May 19, 2025586 Views

    Massives Datenleck in Cloud-Spichenn | CSO online

    May 19, 2025526 Views
    Stay In Touch
    • Facebook
    • YouTube
    • TikTok
    • WhatsApp
    • Twitter
    • Instagram
    Latest Reviews

    Subscribe to Updates

    Get the latest tech news from FooBar about tech, design and biz.

    Most Popular

    Warcraft’s player is darker than imagination compared to the world of housing-raids on the hand

    May 18, 20250 Views

    Switch 2 has two great new features for battery health and safety

    May 18, 20250 Views

    Do I need antivirus software for Windows 11?

    May 18, 20250 Views
    Our Picks

    iOS 26 will help you screen your calls and messages for spam

    June 10, 2025

    Aptos’ APT profit 4%, more possible reverse on important quantity

    June 10, 2025

    SMBs are fretting about rising costs before a hard year

    June 10, 2025

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Facebook X (Twitter) Instagram Pinterest
    • About Us
    • Contact Us
    • Privacy Policy
    • Terms And Conditions
    • Disclaimer
    © 2025 PineapplesUpdate. Designed by Pro.

    Type above and press Enter to search. Press Esc to cancel.