Security Advisory

CVE-2019-16663

8.8
HIGH

Vulnerability Description

An issue was discovered in rConfig 3.9.2. An attacker can directly execute system commands by sending a GET request to search.crud.php because the catCommand parameter is passed to the exec function without filtering, which can lead to command execution.
Published Date October 28, 2019
Official Source NIST NVD Advisory