First published: Fri Aug 20 2021(Updated: )
An arbitrary file deletion vulnerability in rConfig 3.9.5 has been fixed for 3.9.6. This vulnerability gave attackers the ability to send a crafted request to /lib/ajaxHandlers/ajaxDeleteAllLoggingFiles.php by specifying a path in the path parameter and an extension in the ext parameter and delete all the files with that extension in that path.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
rConfig rConfig | =3.9.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2020-25359.
The severity of CVE-2020-25359 is critical with a score of 9.1.
The affected software version is rConfig 3.9.5.
An attacker can exploit CVE-2020-25359 by sending a crafted request to /lib/ajaxHandlers/ajaxDeleteAllLoggingFiles.php with a specified path and extension, allowing them to delete arbitrary files.
Yes, CVE-2020-25359 has been fixed in rConfig version 3.9.6.