CVE-2019-19509 describes an authenticated remote command execution vulnerability in rConfig 3.9.3. A remote, authenticated attacker can execute arbitrary system commands by manipulating the 'path' parameter in a GET request to ajaxArchiveFiles.php, which is then passed unfiltered to the 'exec' function. This vulnerability carries a high CVSS score of 8.8, indicating severe impacts on confidentiality, integrity, and availability. Exploit intelligence shows readily available exploit modules in Metasploit and ExploitDB, and it has been observed in the wild as part of the Gitpaste-12 worm botnet, confirming active exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
3.9.3CPE matchmatch criteria | cpe:2.3:a:rconfig:rconfig:3.9.3:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.