Security Advisory

CVE-2021-29004

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2021-10-11 11:58:33
Last updated 2024-08-03 21:55:12
Assigner mitre
State PUBLISHED

Description

rConfig 3.9.6 is affected by SQL Injection. A user must be authenticated to exploit the vulnerability. If --secure-file-priv in MySQL server is not set and the Mysql server is the same as rConfig, an attacker may successfully upload a webshell to the server and access it remotely.