← back
CVE-2023-46818highCWE-94

CVE-2023-46818

41Vexday Risk Score

Patch soon. It has a working public exploit.

ssvc Attendcvss 7.2epss 14%
from disclosure to weapon0 days
Published on NVDOct 27
metasploitOct 24
exploitation probability
14%top 4% of all CVEs
observed exploitation
nono source reports it
An issue was discovered in ISPConfig before 3.2.11p1. PHP code injection can be achieved in the language file editor by an admin if admin_allow_langedit is enabled.
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Affected products
n/a · n/a