First published: Mon Mar 27 2023(Updated: )
An arbitrary file download vulnerability in rConfig v6.8.0 allows attackers to download sensitive files via a crafted HTTP request.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
rConfig rConfig | =6.8.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-24366 is an arbitrary file download vulnerability in rConfig v6.8.0.
CVE-2023-24366 allows attackers to download sensitive files by sending a crafted HTTP request.
The severity of CVE-2023-24366 is medium with a CVSS score of 6.5.
To fix CVE-2023-24366, you should update rConfig to a version that is not affected by the vulnerability.
You can find more information about CVE-2023-24366 in the following references: [link1], [link2].