PT-2018-3754 · Rconfig · Rconfig

CVE-2020-23148

·

Published

2018-09-11

·

Updated

2022-10-26

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:C/I:N/A:N
Name of the Vulnerable Software and Affected Versions rConfig version 3.9.5
Description The issue arises from the lack of sanitization of the userLogin parameter in the ldap/login.php file of the rConfig utility for managing network device configurations. This allows attackers to perform a LDAP injection, potentially obtaining sensitive information via a crafted POST request to the "ldap/login.php" endpoint, specifically exploiting the userLogin parameter.
Recommendations For rConfig version 3.9.5, consider disabling the ldap/login.php endpoint or restricting access to it until a patch is available to sanitize the userLogin parameter and prevent LDAP injection attacks.

Exploit

Fix

Special Elements Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2021-04425
CVE-2020-23148

Affected Products

Rconfig