Vulnerability Details CVE-2020-12259
rConfig 3.9.4 is vulnerable to reflected XSS. The configDevice.php file improperly validates user input. An attacker can exploit this vulnerability by crafting arbitrary JavaScript in the rid GET parameter of devicemgmnt.php.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.722
EPSS Ranking 98.7%
CVSS Severity
CVSS v3 Score 5.4
CVSS v2 Score 3.5
Products affected by CVE-2020-12259
-
cpe:2.3:a:rconfig:rconfig:3.9.4