EXPOSURES › CVE-2020-10221
CVE-2020-10221
HIGH ⌖ ON CISA KEV · EXPLOITEDrConfig suffered an OS command injection flaw allowing remote attackers to execute arbitrary system commands via the fileName POST parameter.
An OS command injection vulnerability in rConfig's ajaxAddTemplate.php file allowed remote attackers to execute arbitrary system commands by injecting shell metacharacters into the fileName POST parameter. This failure is critical for DIB organizations because it enables remote code execution, leading to potential data breaches, system compromise, and ransomware deployment. Organizations must ensure all software components are patched and monitored for known vulnerabilities, especially those listed in CISA's KEV catalog.
Shame score — The vulnerability was actively exploited in the wild and included in CISA's KEV catalog, indicating negligent patching and avoidable exposure to remote code execution.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
rConfig lib/ajaxHandlers/ajaxAddTemplate.php contains an OS command injection vulnerability that allows remote attackers to execute OS commands via shell metacharacters in the fileName POST parameter.
"rConfig lib/ajaxHandlers/ajaxAddTemplate.php contains an OS command injection vulnerability that allows remote attackers to execute OS commands via shell metacharacters in the fileName POST parameter."