CVE-2018-17984: Ispconfig

High severity, CVSS 7.8. EPSS: 3.4% chance of exploitation in the next 30 days.

An unanchored /[a-z]{2}/ regular expression in ISPConfig before 3.1.13 makes it possible to include arbitrary files, leading to code execution. This is exploitable by authenticated users who have local filesystem access.

Affected products

  • Ispconfig Ispconfig: before 3.1.13 (fixed in 3.1.13)

Published 2018-10-04. Last modified 2026-06-17.