An unanchored /[a-z]{2}/ regular expression in ISPConfig before 3.1.13 makes it possible to include arbitrary files, leading to code execution. This is exploitable by authenticated users who have local filesystem access.
CVSS Vector
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HIspconfig
APPIspconfig< 3.1.13
🟢
PATCH AVAILABLE
Vendor update available. Deploy in standard maintenance cycle.
Tags
RCE
CWE
References
Related vulnerabilities
CVE-2021-3021CRITICAL9.8PL ✓same product
SQL injection w ISPConfig przed wersją 3.2.2
CVE-2020-9398CRITICAL9.8PL ✓same product
SQL Injection w ISPConfig przy włączonej opcji reverse_proxy_panel_allowed
CVE-2012-2087CRITICAL9.8PL ✓same product
ISPConfig 3.0.4.3: nieautoryzowana zmiana uprawnień plików przez interfejs WebDAV
CVE-2023-46818HIGH7.2same product
An issue was discovered in ISPConfig before 3.2.11p1. PHP code injection can be achieved in the language file ...
CVE-2013-3629HIGH8.8same product
ISPConfig 3.0.5.2 has Arbitrary PHP Code Execution