Known Vulnerabilities for Rconfig by Rconfig
Listed below are 10 of the newest known vulnerabilities associated with "Rconfig" by "Rconfig".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-64826 json | rConfig before 8.2.13 contains a path traversal vulnerability that allows authenticated attackers to read arbitrary files by ... | Not Provided | 2026-08-12 | 2026-08-13 |
| CVE-2026-63102 json | rConfig Core before 8.2.8 contains a privilege escalation vulnerability that allows authenticated users to assign arbitrary r... | Not Provided | 2026-07-20 | 2026-07-21 |
| CVE-2023-39110 json | rconfig v3.9.4 was discovered to contain a Server-Side Request Forgery (SSRF) via the path parameter at /ajaxGetFileByPath.ph... | 8.8 - HIGH | 2023-08-01 | 2023-08-04 |
| CVE-2023-39109 json | rconfig v3.9.4 was discovered to contain a Server-Side Request Forgery (SSRF) via the path_a parameter in the doDiff Function... | 8.8 - HIGH | 2023-08-01 | 2023-08-04 |
| CVE-2023-39108 json | rconfig v3.9.4 was discovered to contain a Server-Side Request Forgery (SSRF) via the path_b parameter in the doDiff Function... | 8.8 - HIGH | 2023-08-01 | 2023-08-04 |
| CVE-2023-24366 json | An arbitrary file download vulnerability in rConfig v6.8.0 allows attackers to download sensitive files via a crafted HTTP re... | 6.5 - MEDIUM | 2023-03-27 | 2023-04-03 |
| CVE-2022-45030 json | A SQL injection vulnerability in rConfig 3.9.7 exists via lib/ajaxHandlers/ajaxCompareGetCmdDates.php?command= (this may inte... | 8.8 - HIGH | 2023-04-15 | 2023-04-24 |
| CVE-2022-44384 json | An arbitrary file upload vulnerability in rconfig v3.9.6 allows attackers to execute arbitrary code via a crafted PHP file. | 8.8 - HIGH | 2022-11-17 | 2022-11-18 |
| CVE-2021-29006 json | rConfig 3.9.6 is affected by a Local File Disclosure vulnerability. An authenticated user may successfully download any file ... | 8.8 - HIGH | 2021-10-11 | 2026-07-09 |
| CVE-2021-29005 json | Insecure permission of chmod command on rConfig server 3.9.6 exists. After installing rConfig apache user may execute chmod a... | 8.8 - HIGH | 2021-10-11 | 2026-07-09 |
Known Affected Configurations (CPE V2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Rconfig | Rconfig | 3.9.7 | |||
| Application | Rconfig | Rconfig | 3.9.5 | |||
| Application | Rconfig | Rconfig | 3.9.4 | |||
| Application | Rconfig | Rconfig | 3.9.3 | |||
| Application | Rconfig | Rconfig | 3.9.2 | |||
| Application | Rconfig | Rconfig | 3.9.1 | |||
| Application | Rconfig | Rconfig | 3.9.0 | |||
| Application | Rconfig | Rconfig | 3.8.7 | |||
| Application | Rconfig | Rconfig | 3.8.6 | |||
| Application | Rconfig | Rconfig | 3.8.0 | |||
| Application | Rconfig | Rconfig | 3.7.5 | |||
| Application | Rconfig | Rconfig | 3.6.9 | |||
| Application | Rconfig | Rconfig | 3.6.8 | |||
| Application | Rconfig | Rconfig | 3.6.7 | |||
| Application | Rconfig | Rconfig | 3.6.0 | |||
| Application | Rconfig | Rconfig | 3.5.4 | |||
| Application | Rconfig | Rconfig | 3.5.2 | |||
| Application | Rconfig | Rconfig | 3.5.1 | |||
| Application | Rconfig | Rconfig | 3.5.0 | |||
| Application | Rconfig | Rconfig | 3.1.1 |