rconfig vulnerabilities
CVEs whose affected-version data names the rconfig package. Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
3 CVEsRSS
CVE-2021-29006Medium· 6.5PoCrConfig 3.9.6 is affected by a Local File Disclosure vulnerability
rConfig 3.9.6 is affected by a Local File Disclosure vulnerability. An authenticated user may successfully download any file on the server.
CVE-2021-29005High· 8.8Insecure permission of chmod command on rConfig server 3.9.6 exists
Insecure permission of chmod command on rConfig server 3.9.6 exists. After installing rConfig apache user may execute chmod as root without password which may let an attacker with low privilege to gain root access on server.
CVE-2021-29004High· 8.8rConfig 3.9.6 is affected by SQL Injection
rConfig 3.9.6 is affected by SQL Injection. A user must be authenticated to exploit the vulnerability. If --secure-file-priv in MySQL server is not set and the Mysql server is the same as rConfig, an attacker may successfully upload a we…