Information Disclosure Vulnerability in rConfig by Starkode
CVE-2020-25351
6.5MEDIUM
What is CVE-2020-25351?
An information disclosure vulnerability in rConfig version 3.9.5 allows remote authenticated attackers to read sensitive files on the server by sending specially crafted requests to the /lib/crud/configcompare.crud.php script. This flaw necessitated a security fix in version 3.9.6 to mitigate potential risks associated with unauthorized file access.
