CVE-2020-13778: rConfig

High severity, CVSS 8.8. EPSS: 4.4% chance of exploitation in the next 30 days.

rConfig 3.9.4 and earlier allows authenticated code execution (of system commands) by sending a forged GET request to lib/ajaxHandlers/ajaxAddTemplate.php or lib/ajaxHandlers/ajaxEditTemplate.php.

Affected products

  • rConfig rConfig: up to and including 3.9.4

Published 2020-10-19. Last modified 2026-06-17.