CVE-2020-9425

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
20/03/2020
Last modified:
21/07/2021

Description

An issue was discovered in includes/head.inc.php in rConfig before 3.9.4. An unauthenticated attacker can retrieve saved cleartext credentials via a GET request to settings.php. Because the application was not exiting after a redirect is applied, the rest of the page still executed, resulting in the disclosure of cleartext credentials in the response.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:rconfig:rconfig:*:*:*:*:*:*:*:* 3.9.4 (excluding)