ZeroHour

CVE-2020-25351

PoC
CVSS 3.1
6.5 medium
EPSS
1%p64
Published
()
Modified
Description

An information disclosure vulnerability in rConfig 3.9.5 has been fixed for version 3.9.6. This vulnerability allowed remote authenticated attackers to read files on the system via a crafted request sent to to the /lib/crud/configcompare.crud.php script.

Vendors
rconfig
Products
rconfig
Weakness
CWE-552
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

In the news

No ingested article mentions this CVE yet.