Beveiligingsadvies

CVE-2020-25359

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2021-08-20 18:10:52
Laatst bijgewerkt 2024-08-04 15:33:05
Toegewezen door mitre
CVSS-score geen score
Status PUBLISHED

Beschrijving

An arbitrary file deletion vulnerability in rConfig 3.9.5 has been fixed for 3.9.6. This vulnerability gave attackers the ability to send a crafted request to /lib/ajaxHandlers/ajaxDeleteAllLoggingFiles.php by specifying a path in the path parameter and an extension in the ext parameter and delete all the files with that extension in that path.