Vulnerability record · CVE-2020-12255 · published 18 May 2020
CVE-2020-12255: rConfig unrestricted file upload enables remote code execution
Rconfig · Rconfig
rConfig 3.9.4 validates uploads in vendor.crud.php by content-type only, ignoring file extension and header. An attacker can upload a .php file with a spoofed image/gif content-type and have it executed via vendor.php. This gives code execution on the rConfig host.
Description
rConfig 3.9.4 is vulnerable to remote code execution due to improper validation in the file upload functionality. vendor.crud.php accepts a file upload by checking content-type without considering the file extension and header. Thus, an attacker can exploit this by uploading a .php file to vendor.php that contains arbitrary PHP code and changing the content-type to image/gif.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Automated analysis
high priorityRemote code execution with a high CVSS score and very high EPSS probability, though it requires a low-privileged authenticated account.
What it is
rConfig 3.9.4 validates uploads in vendor.crud.php by content-type only, ignoring file extension and header. An attacker can upload a .php file with a spoofed image/gif content-type and have it executed via vendor.php. This gives code execution on the rConfig host.
Impact
An attacker gains arbitrary PHP code execution on the server, leading to full compromise of the rConfig application and its data. CVSS 3.1 scores it 8.8 (HIGH) with high confidentiality, integrity and availability impact.
Attack surface
Reachable over the network through the vendor file upload endpoint; the CVSS vector shows PR:L, so a low-privileged authenticated account is required, and no user interaction is needed.
Exploitation
Not listed in CISA KEV, but EPSS is 0.52582 (98.9th percentile), indicating high predicted exploitation activity. The only references are third-party advisories, with no public exploit tag in the record.
What to do
- Upgrade rConfig to a version later than 3.9.4 that fixes the upload validation.
- If patching is not possible, restrict access to vendor.crud.php and vendor.php to trusted administrative networks.
- Enforce server-side validation of file extension and content, and store uploads outside the web root with execution disabled.
- Remove or disable unused upload functionality and audit existing uploaded files for PHP content.
Detection
- Monitor web logs for POST requests to vendor.crud.php with multipart uploads and image/gif content-type.
- Alert on newly created .php files in upload or vendor directories.
- Search for PHP files containing unexpected code in upload paths and review file creation times against request logs.
- Watch for requests to vendor.php that execute recently uploaded files.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://gist.github.com/farid007/9f6ad063645d5b1550298c8b9ae953ff | Third Party Advisory |
| https://gist.github.com/farid007/9f6ad063645d5b1550298c8b9ae953ff | Third Party Advisory |
Track CVE-2020-12255 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2020-12255), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.