Arbitrary File Deletion Vulnerability in rConfig by rConfig
CVE-2020-25359

9.1CRITICAL

Key Information:

Vendor

Rconfig

Status
Vendor
CVE Published:
20 August 2021

What is CVE-2020-25359?

An arbitrary file deletion vulnerability identified in rConfig version 3.9.5 permits attackers to manipulate the file management system. By issuing a specially crafted request to /lib/ajaxHandlers/ajaxDeleteAllLoggingFiles.php, an attacker can specify a file path alongside a file extension, leading to the deletion of all files with that extension within the designated path. This oversight highlights potential security risks associated with improper validation of user inputs in file handling processes, warranting immediate attention and updates to mitigate possible exploitation risks.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

References

CVSS V3.1

Score:
9.1
Severity:
CRITICAL
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.