CVE-2019-16663
HIGHrConfig <3.9.2 - Command Injection
Title source: llmDescription
An issue was discovered in rConfig 3.9.2. An attacker can directly execute system commands by sending a GET request to search.crud.php because the catCommand parameter is passed to the exec function without filtering, which can lead to command execution.
Exploits (1)
References (5)
Scores
CVSS v3
8.8
EPSS
0.9407
EPSS Percentile
99.9%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Details
CWE
CWE-78
Status
published
Products (1)
rconfig/rconfig
3.9.2
Published
Oct 28, 2019
Tracked Since
Feb 18, 2026