Arbitrary File Deletion Vulnerability in rConfig by rConfig
CVE-2020-25359
9.1CRITICAL
What is CVE-2020-25359?
An arbitrary file deletion vulnerability identified in rConfig version 3.9.5 permits attackers to manipulate the file management system. By issuing a specially crafted request to /lib/ajaxHandlers/ajaxDeleteAllLoggingFiles.php, an attacker can specify a file path alongside a file extension, leading to the deletion of all files with that extension within the designated path. This oversight highlights potential security risks associated with improper validation of user inputs in file handling processes, warranting immediate attention and updates to mitigate possible exploitation risks.
