CVE-2020-9425 Scanner
Detects 'Information Disclosure' vulnerability in rConfig affects v. before 3.9.4.
Used 3k times · 3.3k assets checked · url
An issue was discovered in includes/head.inc.php in rConfig before 3.9.4. An unauthenticated attacker can retrieve saved cleartext credentials via a GET request to settings.php. Because the application was not exiting after a redirect is applied, the rest of the page still executed, resulting in the disclosure of cleartext credentials in the response.
Detects 'Information Disclosure' vulnerability in rConfig affects v. before 3.9.4.
Used 3k times · 3.3k assets checked · url
S4E maps published CVEs to scanners and forecasts the next disclosure window for your stack.
Create a free account →