#VU32867 Path traversal in rConfig - CVE-2020-15712
Published: July 28, 2020
rConfig
rConfig
Description
The vulnerability allows a remote attacker to perform directory traversal attacks.
The vulnerability exists due to input validation error when processing directory traversal sequences. A remote authenticated attacker can send a specially crafted HTTP request to the "ajaxGetFileByPath.php" script and read arbitrary files on the system.