SQL injection in rConfig - CVE-2020-10220
Published: March 16, 2020 / Updated: June 17, 2021
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary SQL queries in database.
The vulnerability exists due to insufficient sanitization of user-supplied data passed via the commands.inc.php searchColumn parameter. A remote non-authenticated attacker can send a specially crafted request to the affected application and execute arbitrary SQL commands within the application database.
Successful exploitation of this vulnerability may allow a remote attacker to read, delete, modify data in database and gain complete control over the affected application.
Affected software
How to mitigate CVE-2020-10220
Links to Public Exploits and PoC-codes
- Exploit #5735 - rConfig 3.9.4 - 'searchField' Unauthenticated Root Remote Code Execution (June 17, 2021)
- Exploit #5741 - Rconfig 3.x - Chained Remote Code Execution (Metasploit) (June 17, 2021)
- Exploit #2394 - rConfig 3.9 - 'searchColumn' SQL Injection (April 7, 2020)
- Exploit #2321 - CVE-repository ( :beetle: Repository of CVE found by OCD people) (April 7, 2020)
- Exploit #1465 - Rconfig 3.x Chained Remote Code Execution (March 18, 2020)