rconfig has 3 CVEs on record. The median CVSS is 8.8 (high).
CVEs per month
Last 12 months, by publish date
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 8.8
- Publish → KEV
- —
- Last 90 days
- 0 prev 0
rconfig vulnerabilities
CVEs affecting rconfig, newest first. Open any entry for full detail, references, and exploit status.
3 CVEsRSS
CVE-2021-29006Medium· 6.5PoCrConfig 3.9.6 is affected by a Local File Disclosure vulnerability
rConfig 3.9.6 is affected by a Local File Disclosure vulnerability. An authenticated user may successfully download any file on the server.
CVE-2021-29005High· 8.8Insecure permission of chmod command on rConfig server 3.9.6 exists
Insecure permission of chmod command on rConfig server 3.9.6 exists. After installing rConfig apache user may execute chmod as root without password which may let an attacker with low privilege to gain root access on server.
CVE-2021-29004High· 8.8rConfig 3.9.6 is affected by SQL Injection
rConfig 3.9.6 is affected by SQL Injection. A user must be authenticated to exploit the vulnerability. If --secure-file-priv in MySQL server is not set and the Mysql server is the same as rConfig, an attacker may successfully upload a we…