Insecure Update Vulnerability in rConfig by rConfig
CVE-2020-27464
7.8HIGH
What is CVE-2020-27464?
The rConfig application version 3.9.6 and earlier features a vulnerability in its updater.php component, which allows attackers to exploit an insecure update mechanism. By crafting a malicious ZIP file, an unauthorized user can execute arbitrary code on the affected system. This poses a significant security risk, enabling potential compromise of the application and its underlying infrastructure.
