Vulnerability Description
rConfig 3.9.5 is vulnerable to SQL injection. A remote authenticated attacker could send crafted SQL statements to the devices.crud.php script using the custom_Location parameter, which could allow the attacker to view, add, modify, or delete information in the back-end database.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Rconfig | Rconfig | 3.9.5 |
Related Weaknesses (CWE)
References
- https://exchange.xforce.ibmcloud.com/vulnerabilities/184940VDB Entry
- https://www.rconfig.com/downloads/v3-release-notesRelease NotesVendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/184940VDB Entry
- https://www.rconfig.com/downloads/v3-release-notesRelease NotesVendor Advisory
FAQ
What is CVE-2020-15714?
CVE-2020-15714 is a vulnerability with a CVSS score of 8.8 (HIGH). rConfig 3.9.5 is vulnerable to SQL injection. A remote authenticated attacker could send crafted SQL statements to the devices.crud.php script using the custom_Location parameter, which could allow th...
How severe is CVE-2020-15714?
CVE-2020-15714 has been rated HIGH with a CVSS base score of 8.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2020-15714?
Check the references section above for vendor advisories and patch information. Affected products include: Rconfig Rconfig.