CVE-2020-15713

Severity CVSS v4.0:
Pending analysis
Type:
CWE-89 SQL Injection
Publication date:
28/07/2020
Last modified:
28/07/2020

Description

rConfig 3.9.5 is vulnerable to SQL injection. A remote authenticated attacker could send crafted SQL statements to the devices.php script using the sortBy parameter, which could allow the attacker to view, add, modify, or delete information in the back-end database.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:rconfig:rconfig:3.9.5:*:*:*:*:*:*:*