First published: Fri Nov 13 2020(Updated: )
lib/crud/userprocess.php in rConfig 3.9.x before 3.9.7 has an authentication bypass, leading to administrator account creation. This issue has been fixed in 3.9.7.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
rConfig rConfig | >=3.9.0<3.9.7 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2020-13638.
The severity of CVE-2020-13638 is critical with a score of 9.8.
rConfig versions 3.9.0 to 3.9.6 are affected by CVE-2020-13638.
To fix CVE-2020-13638, you should update rConfig to version 3.9.7 or later.
Yes, you can find additional information about CVE-2020-13638 at the following link: https://theguly.github.io/2020/09/rconfig-3.9.4-multiple-vulnerabilities/