Cybersecurity Alerts

Actively Exploited Vulnerabilities

← Back to Cybersecurity Alerts

CVE-2020-10221

rConfig | rConfigAdded 2021-11-03Remediation Deadline 2022-05-03

rConfig OS Command Injection Vulnerability

rConfig lib/ajaxHandlers/ajaxAddTemplate.php contains an OS command injection vulnerability that allows remote attackers to execute OS commands via shell metacharacters in the fileName POST parameter.

Required Action

Apply updates per vendor instructions.

Weakness Classification

CWE-78

References