Files
CVEs-PoC/2020/CVE-2020-12257.md
T
2025-09-29 21:09:30 +02:00

772 B

CVE-2020-12257

Description

rConfig 3.9.4 is vulnerable to cross-site request forgery (CSRF) because it lacks implementation of CSRF protection such as a CSRF token. An attacker can leverage this vulnerability by creating a form (add a user, delete a user, or edit a user).

POC

Reference

No PoCs from references.

Github