CVE-2020-10879
23.03.2020, 22:15
rConfig before 3.9.5 allows command injection by sending a crafted GET request to lib/crud/search.crud.php since the nodeId parameter is passed directly to the exec function without being escaped.
| Vendor | Product | Version |
|---|---|---|
| rconfig | rconfig | 𝑥 < 3.9.5 |
𝑥
= Vulnerable software versions