← back
CVE-2020-10879

CVE-2020-10879

45Vexday Risk Score

No sign of exploitation. It has a public proof of concept.

ssvc Attendepss 84%
exploitation probability
84%top 1% of all CVEs
observed exploitation
nono source reports it
1 public exploit(s)
rConfig before 3.9.5 allows command injection by sending a crafted GET request to lib/crud/search.crud.php since the nodeId parameter is passed directly to the exec function without being escaped.
Affected products
n/a · n/a
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.