PT-2026-71339 · Rconfig · Rconfig
CVSS v4.0
7.1
High
| Vector | AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
rConfig versions prior to 8.2.13
Description
Authenticated attackers can read arbitrary files by supplying unsanitized directory traversal sequences in the
filename GET parameter of the download export() method. By using ../ sequences, an attacker can escape the exports base directory to access sensitive files readable by the web server process, such as application environment files containing database credentials, encryption keys, and mail configuration.Recommendations
Update rConfig to version 8.2.13 or later.
As a temporary mitigation, restrict access to the
download export() method or avoid using the filename parameter until the update is applied.Exploit
Fix
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Rconfig