SQL Injection Vulnerability in rConfig by Rconfig
CVE-2020-23149
7.5HIGH
What is CVE-2020-23149?
The 'dbName' parameter in the 'ajaxDbInstall.php' file of rConfig version 3.9.5 allows for unsanitized input, enabling attackers to exploit the application through SQL injection. This vulnerability could lead to unauthorized access to sensitive database information, compromising data integrity and privacy.
