Remote Code Execution Flaw in rConfig by rConfig
CVE-2020-15715
9.9CRITICAL
What is CVE-2020-15715?
A security vulnerability in rConfig version 3.9.5 enables remote authenticated attackers to execute arbitrary code on the server. This flaw arises from improper handling of user input in the search.crud.php script, specifically through the manipulation of the nodeId parameter. Successful exploitation could allow an attacker to gain control over the affected system, posing significant risks to data integrity and security.
