CVE-2023-46818: Ispconfig

High severity, CVSS 7.2. EPSS: 15.9% chance of exploitation in the next 30 days.

An issue was discovered in ISPConfig before 3.2.11p1. PHP code injection can be achieved in the language file editor by an admin if admin_allow_langedit is enabled.

Affected products

  • Ispconfig Ispconfig: before 3.2.11 (fixed in 3.2.11); version 3.2.11 only

Published 2023-10-27. Last modified 2026-06-17.