← KEV catalog
CISA known exploited vulnerability

CVE-2020-10221

rConfig OS Command Injection Vulnerability

SOURCE FACT

rConfig · rConfig

rConfig lib/ajaxHandlers/ajaxAddTemplate.php contains an OS command injection vulnerability that allows remote attackers to execute OS commands via shell metacharacters in the fileName POST parameter.

Required action

Apply updates per vendor instructions.

CISA notes

https://nvd.nist.gov/vuln/detail/CVE-2020-10221

View source evidence →

CHECK YOUR OUTSIDE-IN INVENTORY

Could this product be present?