First published: Fri Mar 20 2020(Updated: )
An issue was discovered in includes/head.inc.php in rConfig before 3.9.4. An unauthenticated attacker can retrieve saved cleartext credentials via a GET request to settings.php. Because the application was not exiting after a redirect is applied, the rest of the page still executed, resulting in the disclosure of cleartext credentials in the response.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
rConfig rConfig | <3.9.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-9425 is a vulnerability in the rConfig software before version 3.9.4 that allows an unauthenticated attacker to retrieve saved cleartext credentials.
CVE-2020-9425 has a severity rating of 7.5, which is considered high.
An attacker can exploit CVE-2020-9425 by sending a GET request to settings.php and retrieve saved cleartext credentials.
The affected software version for CVE-2020-9425 is rConfig before version 3.9.4.
To fix CVE-2020-9425, update rConfig to version 3.9.4 or newer.