First published: Fri Aug 20 2021(Updated: )
An arbitrary file write vulnerability in lib/AjaxHandlers/ajaxEditTemplate.php of rConfig 3.9.6 allows attackers to execute arbitrary code via a crafted file.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
rConfig rConfig | =3.9.6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2020-27466.
The title of this vulnerability is 'An arbitrary file write vulnerability in lib/AjaxHandlers/ajaxEditTemplate.php of rConfig 3.9.6 allows attackers to execute arbitrary code via a crafted file.'
The severity of CVE-2020-27466 is high.
CVE-2020-27466 allows attackers to execute arbitrary code on rConfig 3.9.6.
Update rConfig to version 3.9.7 or higher to mitigate the vulnerability.