An arbitrary file deletion vulnerability in rConfig 3.9.5 has been fixed for 3.9.6. This vulnerability gave attackers the ability to send a crafted request to /lib/ajaxHandlers/ajaxDeleteAllLoggingFiles.php by specifying a path in the path parameter and an extension in the ext parameter and delete all the files with that extension in that path.
Advisories
Source ID Title
EUVD EUVD EUVD-2020-18046 An arbitrary file deletion vulnerability in rConfig 3.9.5 has been fixed for 3.9.6. This vulnerability gave attackers the ability to send a crafted request to /lib/ajaxHandlers/ajaxDeleteAllLoggingFiles.php by specifying a path in the path parameter and an extension in the ext parameter and delete all the files with that extension in that path.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2024-08-04T15:33:05.611Z

Reserved: 2020-09-14T00:00:00

Link: CVE-2020-25359

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2021-08-20T19:15:08.357

Modified: 2024-11-21T05:17:53.870

Link: CVE-2020-25359

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.