CVE-2026-64826
- EPSS 0.37%
- Veröffentlicht 12.08.2026 20:44:33
- Zuletzt bearbeitet 13.08.2026 20:17:23
rConfig before 8.2.13 contains a path traversal vulnerability that allows authenticated attackers to read arbitrary files by supplying unsanitized directory traversal sequences in the filename GET parameter of the download_export() method. Attackers ...
CVE-2026-63102
- EPSS 0.24%
- Veröffentlicht 20.07.2026 15:31:17
- Zuletzt bearbeitet 19.08.2026 16:31:01
rConfig Core before 8.2.8 contains a privilege escalation vulnerability that allows authenticated users to assign arbitrary roles to any account by submitting an unvalidated role field through the Users API during user creation or profile updates. At...
CVE-2023-39110
- EPSS 3.65%
- Veröffentlicht 01.08.2023 14:15:10
- Zuletzt bearbeitet 21.11.2024 08:14:45
rconfig v3.9.4 was discovered to contain a Server-Side Request Forgery (SSRF) via the path parameter at /ajaxGetFileByPath.php. This vulnerability allows authenticated attackers to make arbitrary requests via injection of crafted URLs.
CVE-2023-39109
- EPSS 3.36%
- Veröffentlicht 01.08.2023 14:15:10
- Zuletzt bearbeitet 21.11.2024 08:14:44
rconfig v3.9.4 was discovered to contain a Server-Side Request Forgery (SSRF) via the path_a parameter in the doDiff Function of /classes/compareClass.php. This vulnerability allows authenticated attackers to make arbitrary requests via injection of ...
CVE-2023-39108
- EPSS 3.36%
- Veröffentlicht 01.08.2023 14:15:10
- Zuletzt bearbeitet 21.11.2024 08:14:44
rconfig v3.9.4 was discovered to contain a Server-Side Request Forgery (SSRF) via the path_b parameter in the doDiff Function of /classes/compareClass.php. This vulnerability allows authenticated attackers to make arbitrary requests via injection of ...
CVE-2022-45030
- EPSS 2.69%
- Veröffentlicht 15.04.2023 02:15:07
- Zuletzt bearbeitet 06.02.2025 16:15:30
A SQL injection vulnerability in rConfig 3.9.7 exists via lib/ajaxHandlers/ajaxCompareGetCmdDates.php?command= (this may interact with secure-file-priv).
CVE-2023-24366
- EPSS 0.71%
- Veröffentlicht 27.03.2023 21:15:11
- Zuletzt bearbeitet 19.02.2025 18:15:22
An arbitrary file download vulnerability in rConfig v6.8.0 allows attackers to download sensitive files via a crafted HTTP request.
CVE-2022-44384
- EPSS 5.01%
- Veröffentlicht 17.11.2022 17:15:13
- Zuletzt bearbeitet 29.04.2025 15:15:51
An arbitrary file upload vulnerability in rconfig v3.9.6 allows attackers to execute arbitrary code via a crafted PHP file.
CVE-2021-29006
- EPSS 5.56%
- Veröffentlicht 11.10.2021 13:15:07
- Zuletzt bearbeitet 09.07.2026 01:16:50
rConfig 3.9.6 is affected by a Local File Disclosure vulnerability. An authenticated user may successfully download any file on the server.
- EPSS 2.14%
- Veröffentlicht 11.10.2021 13:15:07
- Zuletzt bearbeitet 09.07.2026 01:16:50
Insecure permission of chmod command on rConfig server 3.9.6 exists. After installing rConfig apache user may execute chmod as root without password which may let an attacker with low privilege to gain root access on server.