
An issue was discovered in ISPConfig before 3.2.11p1. PHP code injection can be achieved in the language file editor by an admin if admin_allow_langedit is enabled.

An issue was discovered in ISPConfig before 3.2.11p1. PHP code injection can be achieved in the language file editor by an admin if admin_allow_langedit is enabled.
❯ python3 CVE-2023-46818.py
Usage: python3 CVE-2023-46818.py <URL> <username> <password>
Poc of CVE-2023-46818 ISPConfig <= 3.2.11 - Code Injection Vulnerability by hunntr
If you found this project useful or interesting, consider supporting it by giving a ⭐ to the repository!