CVE-2020-25351: rConfig
Medium severity, CVSS 6.5. EPSS: 1.1% chance of exploitation in the next 30 days.
An information disclosure vulnerability in rConfig 3.9.5 has been fixed for version 3.9.6. This vulnerability allowed remote authenticated attackers to read files on the system via a crafted request sent to to the /lib/crud/configcompare.crud.php script.
Affected products
- rConfig rConfig: version 3.9.5 only
Published 2021-08-20. Last modified 2026-06-17.