Loading
rConfig before 3.9.5 allows command injection by sending a crafted GET request to lib/crud/search.crud.php since the nodeId parameter is passed directly to the exec function without being escaped.
Use CWE-78, Rconfig vendor hub and Rconfig product page to widen CVE-2020-10879 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2020-25359, CVE-2023-39110 and CVE-2023-39109 for nearby disclosures in the same product family.