CyberSec.Space Logo
Back to CVE Browser

CVE-2020-10879

CRITICAL
9.8
CVSS Severity Score
EPSS Score0.0910%
EPSS Percentile14.26th
PublishedMar 23, 2020
Last ModifiedNov 21, 2024

Vulnerability Description

rConfig before 3.9.5 allows command injection by sending a crafted GET request to lib/crud/search.crud.php since the nodeId parameter is passed directly to the exec function without being escaped.

Affected Platforms (CPE)

πŸ“¦
Rconfig

Rconfig

< 3.9.5

References & Advisories

Related Vulnerabilities