CVE-2023-46818

HIGH NUCLEI

ISPConfig language_edit.php PHP Code Injection

Title source: metasploit

Description

An issue was discovered in ISPConfig before 3.2.11p1. PHP code injection can be achieved in the language file editor by an admin if admin_allow_langedit is enabled.

Exploits (12)

nomisec WORKING POC 17 stars
by bipbopbup · poc
https://github.com/bipbopbup/CVE-2023-46818-python-exploit
nomisec WORKING POC 15 stars
by ajdumanhug · poc
https://github.com/ajdumanhug/CVE-2023-46818
nomisec WORKING POC 10 stars
by hunntr · poc
https://github.com/hunntr/CVE-2023-46818
nomisec WORKING POC 6 stars
by blindma1den · poc
https://github.com/blindma1den/CVE-2023-46818-Exploit
nomisec WORKING POC 4 stars
by rvizx · poc
https://github.com/rvizx/CVE-2023-46818
nomisec WORKING POC 1 stars
by zs1n · poc
https://github.com/zs1n/CVE-2023-46818
nomisec WORKING POC 1 stars
by ajdumanhug · poc
https://github.com/ajdumanhug/CVE-2022-42092
gitlab WORKING POC
by LaalyS · poc
https://gitlab.com/LaalyS/CVE-2023-46818
nomisec WORKING POC
by vulnerk0 · poc
https://github.com/vulnerk0/CVE-2023-46818
nomisec WORKING POC
by SyFi · poc
https://github.com/SyFi/CVE-2023-46818
nomisec WORKING POC
by engranaabubakar · poc
https://github.com/engranaabubakar/CVE-2023-46818
metasploit WORKING POC EXCELLENT
by syfi, Egidio Romano · rubypocphp
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/linux/http/ispconfig_lang_edit_php_code_injection.rb

Nuclei Templates (1)

ISPConfig - PHP Code Injection
HIGHVERIFIEDby non-things

Scores

CVSS v3 7.2
EPSS 0.8941
EPSS Percentile 99.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-94
Status published
Products (2)
ispconfig/ispconfig 3.2.11
ispconfig/ispconfig < 3.2.11
Published Oct 27, 2023
Tracked Since Feb 18, 2026