CVE-2020-10221highunder attackCWE-78

CVE-2020-10221

Published · Updated

100Vexday Risk Score

Patch now. It under exploitation confirmed by CISA and has a working public exploit.

ssvc Actcvss 8.8epss 77%
from disclosure to weapon4 days
Published on NVDMar 8
1st PoC+4d
CISA KEV+605d
exploitation probability
77%top 1% of all CVEs
observed exploitation
yesCISA + VulnCheck
2 public exploit(s)
Action required by CISAfederal deadline: 2022-05-03

Apply updates per vendor instructions.

In short

rConfig versions up to 3.94 contain a vulnerability where an attacker can execute arbitrary operating system commands by inserting malicious code into the fileName field when adding a template. This happens because the application doesn't properly sanitize user input before passing it to system commands.

Technical detail

CWE-78 OS Command Injection in lib/ajaxHandlers/ajaxAddTemplate.php allows unauthenticated remote attackers to execute arbitrary OS commands via unsanitized shell metacharacters in the fileName POST parameter. The vulnerable code directly uses user input without proper escaping or validation before command execution, enabling command chaining and arbitrary payload execution.

Summary generated and translated by AI from the official description.

The full analysis of this CVE is available in Portuguese →

lib/ajaxHandlers/ajaxAddTemplate.php in rConfig through 3.94 allows remote attackers to execute arbitrary OS commands via shell metacharacters in the fileName POST parameter.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Affected products
n/a · n/a
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.