CyberRota Analysis
This is a critical severity vulnerability with a CVSS score of 9.1. See the original NVD description below for full technical details.
CVE
CVE-2020-25359
Severity
CRITICAL
CVSS
9.1
EPSS
2.25%
Original NVD Description
An arbitrary file deletion vulnerability in rConfig 3.9.5 has been fixed for 3.9.6. This vulnerability gave attackers the ability to send a crafted request to /lib/ajaxHandlers/ajaxDeleteAllLoggingFiles.php by specifying a path in the path parameter and an extension in the ext parameter and delete all the files with that extension in that path.
Related CVEs
Other vulnerabilities affecting the same vendor(s)