← back
CVE-2020-12259

CVE-2020-12259

40Vexday Risk Score

Patch soon. It has a working public exploit.

ssvc Attendepss 96%
exploitation probability
96%top 1% of all CVEs
observed exploitation
nono source reports it
rConfig 3.9.4 is vulnerable to reflected XSS. The configDevice.php file improperly validates user input. An attacker can exploit this vulnerability by crafting arbitrary JavaScript in the rid GET parameter of devicemgmnt.php.
Affected products
n/a · n/a