vendor:
rConfig
by:
vikingfr
8.8
CVSS
HIGH
Authenticated Remote Code Execution
78
CWE
Product Name: rConfig
Affected Version From: 3.9.3
Affected Version To: 3.9.3
Patch Exists: YES
Related CWE: CVE-2019-19509
CPE: a:rconfig:rconfig
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Apache/2.4.6 (CentOS 7.7) OpenSSL/1.0.2k-fips PHP/7.2.24
2019
rConfig 3.9.3 – Authenticated Remote Code Execution
rConfig 3.9.3 is vulnerable to authenticated remote code execution. An attacker can exploit this vulnerability by sending a malicious payload to the target server via the 'sqlQuery' parameter in the 'ajaxServerSettings.php' file. This will allow the attacker to execute arbitrary code on the target server.
Mitigation:
The vendor has released a patch to address this vulnerability. Users should update their rConfig installations to the latest version.