CVE-2020-12256
18.05.2020, 15:15
rConfig 3.9.4 is vulnerable to reflected XSS. The devicemgmnt.php file improperly validates user input. An attacker can exploit this by crafting arbitrary JavaScript in the deviceId GET parameter to devicemgmnt.php.
| Vendor | Product | Version |
|---|---|---|
| rconfig | rconfig | 3.9.4 |
𝑥
= Vulnerable software versions