Executive brief
rConfig through version 3.9.4 contains an OS command injection vulnerability in lib/ajaxHandlers/ajaxAddTemplate.php. Remote authenticated attackers can execute arbitrary OS commands via shell metacharacters in the fileName POST parameter.
Affected products
- rConfig rConfig up to and including 3.9.4
Timeline
- 2020-03-08: disclosed: NVD Published Date
- 2021-11-03: kev added: Date added to CISA Known Exploited Vulnerabilities Catalog