PT-2021-11130 · Rconfig · Rconfig
Published
2021-08-20
·
Updated
2022-10-05
·
CVE-2020-25359
CVSS v3.1
9.1
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H |
Name of the Vulnerable Software and Affected Versions:
rConfig versions 3.9.5
Description:
An arbitrary file deletion issue allows attackers to delete files by sending a crafted request to "/lib/ajaxHandlers/ajaxDeleteAllLoggingFiles.php" and specifying a path in the
path parameter and an extension in the ext parameter. This enables the deletion of all files with the specified extension in the given path.Recommendations:
For rConfig version 3.9.5, update to version 3.9.6 to resolve the issue. As a temporary workaround, consider restricting access to the "/lib/ajaxHandlers/ajaxDeleteAllLoggingFiles.php" endpoint until the update is applied. Avoid using the
path and ext parameters in the affected API endpoint until the issue is resolved.Exploit
Fix
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Rconfig