/Vulnerability Library

rConfig <= 3.9.4 - Authenticated OS Command Injection

CVE-2020-10221
Verified

Description

lib/ajaxHandlers/ajaxAddTemplate.php in rConfig through 3.9.4 does not properly sanitize the fileName POST parameter before using it in a shell command, allowing an authenticated attacker to inject arbitrary OS commands. This template uses default admin credentials to log in before triggering the injection; override the username / userpassword fields for environments with changed credentials.

Severity

High

CVSS Score

8.8

Exploit Probability

77%

Affected Product

rconfig

Published Date

July 14, 2026

Template Author

jayachandran from securin labs (https://securin.io)

CVE-2020-10221.yaml
8.8Score

CVSS Metrics

CVSS Vector:
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVE ID:
cve-2020-10221
CWE ID:
cwe-78

References

https://github.com/advisories/GHSA-hxjm-95v4-6qjjhttps://www.exploit-db.com/exploits/48207https://nvd.nist.gov/vuln/detail/CVE-2020-10221

Remediation Steps

Upgrade rConfig beyond 3.9.4 once a fixed release is available, or restrict access to /lib/ajaxHandlers/ and change default credentials.