← Vulnerability feed

Vulnerability record · CVE-2020-12255 · published 18 May 2020

CVE-2020-12255: rConfig unrestricted file upload enables remote code execution

Rconfig · Rconfig

rConfig 3.9.4 validates uploads in vendor.crud.php by content-type only, ignoring file extension and header. An attacker can upload a .php file with a spoofed image/gif content-type and have it executed via vendor.php. This gives code execution on the rConfig host.

8.8 CVSS 3.1 High EPSS 53% · top 1.1% CWE-434 · Unrestricted file upload
8.8CVSS 3.1 base score, v2 6.5
53%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References
17 Jun 2026Last modified by NVD

Description

rConfig 3.9.4 is vulnerable to remote code execution due to improper validation in the file upload functionality. vendor.crud.php accepts a file upload by checking content-type without considering the file extension and header. Thus, an attacker can exploit this by uploading a .php file to vendor.php that contains arbitrary PHP code and changing the content-type to image/gif.

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 20 September 2026. Confidence: high.

high priorityRemote code execution with a high CVSS score and very high EPSS probability, though it requires a low-privileged authenticated account.

What it is

rConfig 3.9.4 validates uploads in vendor.crud.php by content-type only, ignoring file extension and header. An attacker can upload a .php file with a spoofed image/gif content-type and have it executed via vendor.php. This gives code execution on the rConfig host.

Impact

An attacker gains arbitrary PHP code execution on the server, leading to full compromise of the rConfig application and its data. CVSS 3.1 scores it 8.8 (HIGH) with high confidentiality, integrity and availability impact.

Attack surface

Reachable over the network through the vendor file upload endpoint; the CVSS vector shows PR:L, so a low-privileged authenticated account is required, and no user interaction is needed.

Exploitation

Not listed in CISA KEV, but EPSS is 0.52582 (98.9th percentile), indicating high predicted exploitation activity. The only references are third-party advisories, with no public exploit tag in the record.

What to do

  • Upgrade rConfig to a version later than 3.9.4 that fixes the upload validation.
  • If patching is not possible, restrict access to vendor.crud.php and vendor.php to trusted administrative networks.
  • Enforce server-side validation of file extension and content, and store uploads outside the web root with execution disabled.
  • Remove or disable unused upload functionality and audit existing uploaded files for PHP content.

Detection

  • Monitor web logs for POST requests to vendor.crud.php with multipart uploads and image/gif content-type.
  • Alert on newly created .php files in upload or vendor directories.
  • Search for PHP files containing unexpected code in upload paths and review file creation times against request logs.
  • Watch for requests to vendor.php that execute recently uploaded files.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2020-12255 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.8CVE-2020-10221rConfig ajaxAddTemplate.php OS command injection via fileNamerConfig through 3.94 passes the fileName POST parameter in lib/ajaxHandlers/ajaxAddTemplate.php to a shell without sanitization, allowing OS command …KEVEPSS 77%analysed9.9CVE-2020-15715Rconfig vulnerabilityrConfig 3.9.5 could allow a remote authenticated attacker to execute arbitrary code on the system, because of an error in the search.crud.php script.…EPSS 4.2%9.8CVE-2020-23151Rconfig os command injection vulnerabilityrConfig 3.9.5 allows command injection by sending a crafted GET request to lib/ajaxHandlers/ajaxArchiveFiles.php since the path parameter is passed d…EPSS 5.7%9.8CVE-2020-13638rConfig authentication bypass allows admin account creationrConfig 3.9.x before 3.9.7 contains an authentication bypass in lib/crud/userprocess.php that lets an unauthenticated attacker create an administrato…EPSS 77%analysed9.8CVE-2020-10548Rconfig sql injection vulnerabilityrConfig 3.9.4 and previous versions has unauthenticated devices.inc.php SQL injection. Because, by default, nodes' passwords are stored in cleartext,…EPSS 37%9.8CVE-2020-10549Rconfig sql injection vulnerabilityrConfig 3.9.4 and previous versions has unauthenticated snippets.inc.php SQL injection. Because, by default, nodes' passwords are stored in cleartext…EPSS 32%9.8CVE-2020-10546rConfig unauthenticated SQL injection in compliancepolicies.inc.phprConfig 3.9.4 and earlier contains an unauthenticated SQL injection in compliancepolicies.inc.php. Because node passwords are stored in cleartext by …EPSS 87%analysed9.8CVE-2020-10547Rconfig sql injection vulnerabilityrConfig 3.9.4 and previous versions has unauthenticated compliancepolicyelements.inc.php SQL injection. Because, by default, nodes' passwords are sto…EPSS 37%

Source: NIST National Vulnerability Database (record CVE-2020-12255), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.