CVE-2020-10879
23.03.2020, 22:15
rConfig before 3.9.5 allows command injection by sending a crafted GET request to lib/crud/search.crud.php since the nodeId parameter is passed directly to the exec function without being escaped.
Vendor | Product | Version |
---|---|---|
rconfig | rconfig | 𝑥 < 3.9.5 |
𝑥
= Vulnerable software versions