ZeroHour

CVE-2020-15715

CVSS 3.1
9.9 critical
EPSS
4%p90
Published
()
Modified
Description

rConfig 3.9.5 could allow a remote authenticated attacker to execute arbitrary code on the system, because of an error in the search.crud.php script. An attacker could exploit this vulnerability using the nodeId parameter.

Vendors
rconfig
Products
rconfig
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.