PT-2021-10843 · Rconfig · Rconfig

Published

2021-08-09

·

Updated

2021-08-12

·

CVE-2020-23149

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions rConfig version 3.9.5
Description The issue allows attackers to perform a SQL injection and access sensitive database information due to the unsanitized dbName parameter in the ajaxDbInstall.php file.
Recommendations For rConfig version 3.9.5, consider sanitizing the dbName parameter in the ajaxDbInstall.php file to prevent SQL injection attacks. As a temporary workaround, restrict access to the ajaxDbInstall.php file until a patch is available.

Exploit

Fix

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-23149

Affected Products

Rconfig