Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2023-39109

rconfig v3.9.4 was discovered to contain a Server-Side Request Forgery (SSRF) via the path_a parameter in the doDiff Function of /classes/compareClass.php. This vulnerability allows authenticated attackers to make arbitrary requests via injection of crafted URLs.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.801
EPSS Ranking 99.1%
CVSS Severity
CVSS v3 Score 8.8
Products affected by CVE-2023-39109
  • Rconfig » Rconfig » Version: 3.9.4
    cpe:2.3:a:rconfig:rconfig:3.9.4


Contact Us

Shodan ® - All rights reserved