RULE(RULE ID:337791)

Rule General Information
Release Date: 2024-01-16
Rule Name: rConfig v3.9.4 Server Side Request Forgery Vulnerability (CVE-2023-39110)
Severity:
CVE ID:
Rule Protection Details
Description: rconfig v3.9.4 was discovered to contain a Server-Side Request Forgery (SSRF) via the path parameter at /ajaxGetFileByPath.php. This vulnerability allows authenticated attackers to make arbitrary requests via injection of crafted URLs.
Impact: SSRF is a security vulnerability constructed by an attacker to form a request initiated by a server. By exploiting this vulnerability, an attacker can bypass access restrictions such as firewalls, thereby using an infected or vulnerable server as a proxy for port scanning and even accessing internal system data.
Affected OS: Windows, Linux, Others
Reference: https://github.com/zer0yu/CVE_Request/blob/master/rConfig/rConfig_
https://cxsecurity.com/cveshow/CVE-2023-39110/
Solutions
Please contact the software vendor to update the software patch.