Rconfig

Rconfig

48 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.41%
  • Veröffentlicht 24.08.2026 16:11:44
  • Zuletzt bearbeitet 24.09.2026 20:43:32

rConfig Core 8.0.0 before 8.2.10 contains an authentication bypass vulnerability that allows unauthenticated attackers to self-register accounts with full Administrator privileges due to a duplicate bare Auth::routes() call in routes/web.php that re-...

  • EPSS 0.54%
  • Veröffentlicht 24.08.2026 16:07:58
  • Zuletzt bearbeitet 23.09.2026 18:14:58

rConfig Core 8.0.0 before 8.2.13 contains a path traversal vulnerability that allows authenticated users to read arbitrary files by supplying crafted filenames containing directory traversal sequences to the export download endpoint. Attackers can ma...

  • EPSS 0.37%
  • Veröffentlicht 12.08.2026 20:44:33
  • Zuletzt bearbeitet 09.09.2026 20:36:38

rConfig before 8.2.13 contains a path traversal vulnerability that allows authenticated attackers to read arbitrary files by supplying unsanitized directory traversal sequences in the filename GET parameter of the download_export() method. Attackers ...

  • EPSS 0.24%
  • Veröffentlicht 20.07.2026 15:31:17
  • Zuletzt bearbeitet 19.08.2026 16:31:01

rConfig Core before 8.2.8 contains a privilege escalation vulnerability that allows authenticated users to assign arbitrary roles to any account by submitting an unvalidated role field through the Users API during user creation or profile updates. At...

Exploit
  • EPSS 3.65%
  • Veröffentlicht 01.08.2023 14:15:10
  • Zuletzt bearbeitet 21.11.2024 08:14:45

rconfig v3.9.4 was discovered to contain a Server-Side Request Forgery (SSRF) via the path parameter at /ajaxGetFileByPath.php. This vulnerability allows authenticated attackers to make arbitrary requests via injection of crafted URLs.

Exploit
  • EPSS 3.36%
  • Veröffentlicht 01.08.2023 14:15:10
  • Zuletzt bearbeitet 21.11.2024 08:14:44

rconfig v3.9.4 was discovered to contain a Server-Side Request Forgery (SSRF) via the path_a parameter in the doDiff Function of /classes/compareClass.php. This vulnerability allows authenticated attackers to make arbitrary requests via injection of ...

Exploit
  • EPSS 3.36%
  • Veröffentlicht 01.08.2023 14:15:10
  • Zuletzt bearbeitet 21.11.2024 08:14:44

rconfig v3.9.4 was discovered to contain a Server-Side Request Forgery (SSRF) via the path_b parameter in the doDiff Function of /classes/compareClass.php. This vulnerability allows authenticated attackers to make arbitrary requests via injection of ...

Exploit
  • EPSS 2.69%
  • Veröffentlicht 15.04.2023 02:15:07
  • Zuletzt bearbeitet 06.02.2025 16:15:30

A SQL injection vulnerability in rConfig 3.9.7 exists via lib/ajaxHandlers/ajaxCompareGetCmdDates.php?command= (this may interact with secure-file-priv).

  • EPSS 0.71%
  • Veröffentlicht 27.03.2023 21:15:11
  • Zuletzt bearbeitet 19.02.2025 18:15:22

An arbitrary file download vulnerability in rConfig v6.8.0 allows attackers to download sensitive files via a crafted HTTP request.

Exploit
  • EPSS 5.01%
  • Veröffentlicht 17.11.2022 17:15:13
  • Zuletzt bearbeitet 29.04.2025 15:15:51

An arbitrary file upload vulnerability in rconfig v3.9.6 allows attackers to execute arbitrary code via a crafted PHP file.