An issue was discovered in rConfig 3.9.2. An attacker can directly execute system commands by sending a GET request to search.crud.php because the catCommand parameter is passed to the exec function without filtering, which can lead to command execution.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.939
EPSS Ranking 99.9%