CVE-2023-46818
HIGH NUCLEIISPConfig language_edit.php PHP Code Injection
Title source: metasploitDescription
An issue was discovered in ISPConfig before 3.2.11p1. PHP code injection can be achieved in the language file editor by an admin if admin_allow_langedit is enabled.
Exploits (12)
nomisec
WORKING POC
17 stars
by bipbopbup · poc
https://github.com/bipbopbup/CVE-2023-46818-python-exploit
nomisec
WORKING POC
6 stars
by blindma1den · poc
https://github.com/blindma1den/CVE-2023-46818-Exploit
metasploit
WORKING POC
EXCELLENT
by syfi, Egidio Romano · rubypocphp
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/linux/http/ispconfig_lang_edit_php_code_injection.rb
Nuclei Templates (1)
ISPConfig - PHP Code Injection
HIGHVERIFIEDby non-things
Scores
CVSS v3
7.2
EPSS
0.8941
EPSS Percentile
99.5%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Details
CWE
CWE-94
Status
published
Products (2)
ispconfig/ispconfig
3.2.11
ispconfig/ispconfig
< 3.2.11
Published
Oct 27, 2023
Tracked Since
Feb 18, 2026