CVE-2019-19372: rConfig
High severity, CVSS 7.5. EPSS: 1.5% chance of exploitation in the next 30 days.
A downloadFile.php download_file path traversal vulnerability in rConfig through 3.9.3 allows attackers to list files in arbitrary folders and potentially download files. NOTE: the discoverer later reported that there was not a "fully working exploit.
Affected products
- rConfig rConfig: up to and including 3.9.3
Published 2019-11-28. Last modified 2026-06-17.