Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-24vx-3r2r-h4mc

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

rConfig 3.9.4 and previous versions has unauthenticated snippets.inc.php SQL injection. Because, by default, nodes' passwords are stored in cleartext, this vulnerability leads to lateral movement, granting an attacker access to monitored network devices.

rConfig 3.9.4 and previous versions has unauthenticated snippets.inc.php SQL injection. Because, by default, nodes' passwords are stored in cleartext, this vulnerability leads to lateral movement, granting an attacker access to monitored network devices.

EPSS

Процентиль: 100%
0.92086
Критический

Дефекты

CWE-89

Связанные уязвимости

CVSS3: 9.8
nvd
около 5 лет назад

rConfig 3.9.4 and previous versions has unauthenticated snippets.inc.php SQL injection. Because, by default, nodes' passwords are stored in cleartext, this vulnerability leads to lateral movement, granting an attacker access to monitored network devices.

EPSS

Процентиль: 100%
0.92086
Критический

Дефекты

CWE-89