PT-2018-3754 · Rconfig · Rconfig
CVE-2020-23148
·
Publicado
2018-09-11
·
Atualizado
2022-10-26
CVSS v2.0
7.8
Alta
| Vetor | AV:N/AC:L/Au:N/C:C/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
rConfig version 3.9.5
Description
The issue arises from the lack of sanitization of the
userLogin parameter in the ldap/login.php file of the rConfig utility for managing network device configurations. This allows attackers to perform a LDAP injection, potentially obtaining sensitive information via a crafted POST request to the "ldap/login.php" endpoint, specifically exploiting the userLogin parameter.Recommendations
For rConfig version 3.9.5, consider disabling the
ldap/login.php endpoint or restricting access to it until a patch is available to sanitize the userLogin parameter and prevent LDAP injection attacks.Exploit
Correção
Special Elements Injection
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Rconfig