CISA Known Exploited Vulnerability

CVE-2020-10221

rConfig · rConfig

rConfig OS Command Injection Vulnerability

Date added
BOD 22-01 due date
CWE CWE-78
Ransomware Unknown

CISA description

rConfig lib/ajaxHandlers/ajaxAddTemplate.php contains an OS command injection vulnerability that allows remote attackers to execute OS commands via shell metacharacters in the fileName POST parameter.

Required action

Apply updates per vendor instructions.