Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2020-9425

An issue was discovered in includes/head.inc.php in rConfig before 3.9.4. An unauthenticated attacker can retrieve saved cleartext credentials via a GET request to settings.php. Because the application was not exiting after a redirect is applied, the rest of the page still executed, resulting in the disclosure of cleartext credentials in the response.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.316
EPSS Ranking 96.6%
CVSS Severity
CVSS v3 Score 7.5
CVSS v2 Score 5.0
Products affected by CVE-2020-9425


Contact Us

Shodan ® - All rights reserved