First published: Mon Mar 23 2020(Updated: )
rConfig before 3.9.5 allows command injection by sending a crafted GET request to lib/crud/search.crud.php since the nodeId parameter is passed directly to the exec function without being escaped.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
rConfig rConfig | <3.9.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-10879 is a vulnerability in rConfig before version 3.9.5 that allows command injection through a crafted GET request.
The severity of CVE-2020-10879 is critical with a CVSS score of 9.8.
CVE-2020-10879 affects rConfig versions up to and excluding 3.9.5.
CVE-2020-10879 can be exploited by sending a crafted GET request to the lib/crud/search.crud.php endpoint with a malicious nodeId parameter.
To fix CVE-2020-10879, upgrade to rConfig version 3.9.5 or later.