← Back to CVE List

CVE-2020-9425

Published: 2020-03-20T18:15Z
Last Modified: 2024-11-21T05:40Z
Source: MITRE CVE List
License: MITRE-CVE-TOS
An issue was discovered in includes/head.inc.php in rConfig before 3.9.4. An unauthenticated attacker can retrieve saved cleartext credentials via a GET request to settings.php. Because the application was not exiting after a redirect is applied, the rest of the page still executed, resulting in the disclosure of cleartext credentials in the response. > MITRE Terms of Use apply – see LICENSE‑MITRE.txt