First published: Mon Aug 09 2021(Updated: )
A SQL injection vulnerability in config.inc.php of rConfig 3.9.5 allows attackers to access sensitive database information via a crafted GET request to install/lib/ajaxHandlers/ajaxDbInstall.php.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
rConfig rConfig | =3.9.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-23150 is a SQL injection vulnerability in the config.inc.php file of rConfig 3.9.5.
CVE-2020-23150 allows attackers to access sensitive database information by exploiting a SQL injection vulnerability in rConfig 3.9.5.
CVE-2020-23150 has a severity rating of 7.5 (High).
To fix CVE-2020-23150, it is recommended to update rConfig to version 3.9.6 or later, which includes a patch for this vulnerability.
You can find more information about CVE-2020-23150 on the official GitHub page of rConfig.