CVE-2020-10221 | rConfig up to 3.94 ajaxAddTemplate.php fileName os command injection (ID 156687 / EDB-48207)
A vulnerability was found in rConfig up to 3.94. It has been declared as critical. This vulnerability affects unknown code in the library lib/ajaxHandlers/ajaxAddTemplate.php. The manipulation of the argument fileName as part of Shell Metacharacter leads to os command injection.
This vulnerability was named CVE-2020-10221. The attack can be initiated remotely. Furthermore, there is an exploit available.