Skip to content
COOEY

EXPOSURES › CVE-2020-10221

CVE-2020-10221

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2021-11-03 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2020-10221 ↗
⚡ RCE ⌖ EXPLOITED IN THE WILD SHAME 78/100 rceexploited-in-wildunpatched

rConfig suffered an OS command injection flaw allowing remote attackers to execute arbitrary system commands via the fileName POST parameter.

An OS command injection vulnerability in rConfig's ajaxAddTemplate.php file allowed remote attackers to execute arbitrary system commands by injecting shell metacharacters into the fileName POST parameter. This failure is critical for DIB organizations because it enables remote code execution, leading to potential data breaches, system compromise, and ransomware deployment. Organizations must ensure all software components are patched and monitored for known vulnerabilities, especially those listed in CISA's KEV catalog.

Shame score — The vulnerability was actively exploited in the wild and included in CISA's KEV catalog, indicating negligent patching and avoidable exposure to remote code execution.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

rConfig lib/ajaxHandlers/ajaxAddTemplate.php contains an OS command injection vulnerability that allows remote attackers to execute OS commands via shell metacharacters in the fileName POST parameter.

SENTIMENT · TRUSTED SOURCES
synthesis severe-fallout -0.60
rConfig's OS command injection flaw was widely condemned as a severe security failure allowing remote attackers to execute arbitrary commands, with no positive coverage found in the provided sources.
cooey ↗ severe-fallout -1.00
severe condemnation of the OS command injection vulnerability allowing remote attackers to execute arbitrary commands.
"rConfig lib/ajaxHandlers/ajaxAddTemplate.php contains an OS command injection vulnerability that allows remote attackers to execute OS commands via shell metacharacters in the fileName POST parameter."
CISA ↗ severe-fallout +0.00
neutral; source is unrelated to rConfig/CVE-2020-10221.
nypost.com ↗ severe-fallout +0.00
neutral; source is unrelated to rConfig/CVE-2020-10221.
www.cvefind.com ↗ severe-fallout +0.00
neutral; source is unrelated to rConfig/CVE-2020-10221.
www.dell.com ↗ severe-fallout +0.00
neutral; source is unrelated to rConfig/CVE-2020-10221.
cybersecuritynews.com ↗ severe-fallout +0.00
neutral; source is unrelated to rConfig/CVE-2020-10221.
www.arista.com ↗ severe-fallout +0.00
neutral; source is unrelated to rConfig/CVE-2020-10221.
AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.