Known Vulnerabilities for products from Rconfig
Listed below are 20 of the newest known vulnerabilities associated with the vendor "Rconfig".
These CVEs are retrieved based on exact matches on listed vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed vendor information are still displayed.
Data on known vulnerable products is also displayed based on information from known CPEs, each product links to its respective vulnerability page.
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-63102 json | Not Provided | 2026-07-20 | 2026-07-20 | |
| CVE-2023-39110 json | rconfig v3.9.4 was discovered to contain a Server-Side Request Forgery (SSRF) via the path parameter at /ajaxGetFileByPath.ph... | 8.8 - HIGH | 2023-08-01 | 2023-08-04 |
| CVE-2023-39109 json | rconfig v3.9.4 was discovered to contain a Server-Side Request Forgery (SSRF) via the path_a parameter in the doDiff Function... | 8.8 - HIGH | 2023-08-01 | 2023-08-04 |
| CVE-2023-39108 json | rconfig v3.9.4 was discovered to contain a Server-Side Request Forgery (SSRF) via the path_b parameter in the doDiff Function... | 8.8 - HIGH | 2023-08-01 | 2023-08-04 |
| CVE-2023-24366 json | An arbitrary file download vulnerability in rConfig v6.8.0 allows attackers to download sensitive files via a crafted HTTP re... | 6.5 - MEDIUM | 2023-03-27 | 2023-04-03 |
| CVE-2022-45030 json | A SQL injection vulnerability in rConfig 3.9.7 exists via lib/ajaxHandlers/ajaxCompareGetCmdDates.php?command= (this may inte... | 8.8 - HIGH | 2023-04-15 | 2023-04-24 |
| CVE-2022-44384 json | An arbitrary file upload vulnerability in rconfig v3.9.6 allows attackers to execute arbitrary code via a crafted PHP file. | 8.8 - HIGH | 2022-11-17 | 2022-11-18 |
| CVE-2021-29006 json | rConfig 3.9.6 is affected by a Local File Disclosure vulnerability. An authenticated user may successfully download any file ... | Not Provided | 2021-10-11 | 2026-07-09 |
| CVE-2021-29005 json | Insecure permission of chmod command on rConfig server 3.9.6 exists. After installing rConfig apache user may execute chmod a... | Not Provided | 2021-10-11 | 2026-07-09 |
| CVE-2021-29004 json | Not Provided | 2021-10-11 | 2026-07-09 | |
| CVE-2020-27466 json | An arbitrary file write vulnerability in lib/AjaxHandlers/ajaxEditTemplate.php of rConfig 3.9.6 allows attackers to execute a... | 7.8 - HIGH | 2021-08-20 | 2021-08-24 |
| CVE-2020-27464 json | An insecure update feature in the /updater.php component of rConfig 3.9.6 and below allows attackers to execute arbitrary cod... | 7.8 - HIGH | 2021-08-20 | 2021-08-23 |
| CVE-2020-25359 json | An arbitrary file deletion vulnerability in rConfig 3.9.5 has been fixed for 3.9.6. This vulnerability gave attackers the abi... | 9.1 - CRITICAL | 2021-08-20 | 2022-10-05 |
| CVE-2020-25353 json | A server-side request forgery (SSRF) vulnerability in rConfig 3.9.5 has been fixed for 3.9.6. This vulnerability allowed remo... | 6.5 - MEDIUM | 2021-08-20 | 2021-08-24 |
| CVE-2020-25352 json | A stored cross-site scripting (XSS) vulnerability in the /devices.php function inrConfig 3.9.5 has been fixed for version 3.9... | 5.4 - MEDIUM | 2021-08-20 | 2021-08-23 |
| CVE-2020-25351 json | An information disclosure vulnerability in rConfig 3.9.5 has been fixed for version 3.9.6. This vulnerability allowed remote ... | 6.5 - MEDIUM | 2021-08-20 | 2021-08-23 |
| CVE-2020-23151 json | rConfig 3.9.5 allows command injection by sending a crafted GET request to lib/ajaxHandlers/ajaxArchiveFiles.php since the pa... | 9.8 - CRITICAL | 2021-08-09 | 2022-10-26 |
| CVE-2020-23150 json | A SQL injection vulnerability in config.inc.php of rConfig 3.9.5 allows attackers to access sensitive database information vi... | 7.5 - HIGH | 2021-08-09 | 2021-08-12 |
| CVE-2020-23149 json | The dbName parameter in ajaxDbInstall.php of rConfig 3.9.5 is unsanitized, allowing attackers to perform a SQL injection and ... | 7.5 - HIGH | 2021-08-09 | 2021-08-12 |
| CVE-2020-23148 json | The userLogin parameter in ldap/login.php of rConfig 3.9.5 is unsanitized, allowing attackers to perform a LDAP injection and... | 7.5 - HIGH | 2021-08-09 | 2022-10-26 |
Known software with vulnerabilities from Rconfig
| Type | Vendor | Product | Version |
|---|---|---|---|
| Application | Rconfig | Rconfig | 1.0.0 |