CVE-2020-27464: rConfig
High severity, CVSS 7.8. EPSS: 2.5% chance of exploitation in the next 30 days.
An insecure update feature in the /updater.php component of rConfig 3.9.6 and below allows attackers to execute arbitrary code via a crafted ZIP file.
Affected products
- rConfig rConfig: up to and including 3.9.6
Published 2021-08-20. Last modified 2026-06-17.