Known Vulnerabilities for Rconfig by Rconfig
Listed below are 10 of the newest known vulnerabilities associated with "Rconfig" by "Rconfig".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-63102 json | rConfig Core before 8.2.8 contains a privilege escalation vulnerability that allows authenticated users to assign arbitrary r... | Not Provided | 2026-07-20 | 2026-07-20 |
| CVE-2023-39110 json | rconfig v3.9.4 was discovered to contain a Server-Side Request Forgery (SSRF) via the path parameter at /ajaxGetFileByPath.ph... | 8.8 - HIGH | 2023-08-01 | 2023-08-04 |
| CVE-2023-39109 json | rconfig v3.9.4 was discovered to contain a Server-Side Request Forgery (SSRF) via the path_a parameter in the doDiff Function... | 8.8 - HIGH | 2023-08-01 | 2023-08-04 |
| CVE-2023-39108 json | rconfig v3.9.4 was discovered to contain a Server-Side Request Forgery (SSRF) via the path_b parameter in the doDiff Function... | 8.8 - HIGH | 2023-08-01 | 2023-08-04 |
| CVE-2023-24366 json | An arbitrary file download vulnerability in rConfig v6.8.0 allows attackers to download sensitive files via a crafted HTTP re... | 6.5 - MEDIUM | 2023-03-27 | 2023-04-03 |
| CVE-2022-45030 json | A SQL injection vulnerability in rConfig 3.9.7 exists via lib/ajaxHandlers/ajaxCompareGetCmdDates.php?command= (this may inte... | 8.8 - HIGH | 2023-04-15 | 2023-04-24 |
| CVE-2022-44384 json | An arbitrary file upload vulnerability in rconfig v3.9.6 allows attackers to execute arbitrary code via a crafted PHP file. | 8.8 - HIGH | 2022-11-17 | 2022-11-18 |
| CVE-2021-29006 json | rConfig 3.9.6 is affected by a Local File Disclosure vulnerability. An authenticated user may successfully download any file ... | 8.8 - HIGH | 2021-10-11 | 2026-07-09 |
| CVE-2021-29005 json | Insecure permission of chmod command on rConfig server 3.9.6 exists. After installing rConfig apache user may execute chmod a... | 8.8 - HIGH | 2021-10-11 | 2026-07-09 |
| CVE-2021-29004 json | rConfig 3.9.6 is affected by SQL Injection. A user must be authenticated to exploit the vulnerability. If --secure-file-priv ... | 8.8 - HIGH | 2021-10-11 | 2026-07-09 |
Known Affected Configurations (CPE V2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Rconfig | Rconfig | 3.9.7 | |||
| Application | Rconfig | Rconfig | 3.9.5 | |||
| Application | Rconfig | Rconfig | 3.9.4 | |||
| Application | Rconfig | Rconfig | 3.9.3 | |||
| Application | Rconfig | Rconfig | 3.9.2 | |||
| Application | Rconfig | Rconfig | 3.9.1 | |||
| Application | Rconfig | Rconfig | 3.9.0 | |||
| Application | Rconfig | Rconfig | 3.8.7 | |||
| Application | Rconfig | Rconfig | 3.8.6 | |||
| Application | Rconfig | Rconfig | 3.8.0 | |||
| Application | Rconfig | Rconfig | 3.7.5 | |||
| Application | Rconfig | Rconfig | 3.6.9 | |||
| Application | Rconfig | Rconfig | 3.6.8 | |||
| Application | Rconfig | Rconfig | 3.6.7 | |||
| Application | Rconfig | Rconfig | 3.6.0 | |||
| Application | Rconfig | Rconfig | 3.5.4 | |||
| Application | Rconfig | Rconfig | 3.5.2 | |||
| Application | Rconfig | Rconfig | 3.5.1 | |||
| Application | Rconfig | Rconfig | 3.5.0 | |||
| Application | Rconfig | Rconfig | 3.1.1 |