CVE-2020-10221

rConfig OS Command Injection Vulnerability

Description

rConfig lib/ajaxHandlers/ajaxAddTemplate.php contains an OS command injection vulnerability that allows remote attackers to execute OS commands via shell metacharacters in the fileName POST parameter.

Severity: HIGH

CVSS Score: 8.8

Vendor: rConfig

Product: rConfig

Loading CVE details...