4.6
CVSSv2

CVE-2018-17984

Published: 04/10/2018 Updated: 13/12/2018
CVSS v2 Base Score: 4.6 | Impact Score: 6.4 | Exploitability Score: 3.9
CVSS v3 Base Score: 7.8 | Impact Score: 5.9 | Exploitability Score: 1.8
VMScore: 409
Vector: AV:L/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

An unanchored /[a-z]{2}/ regular expression in ISPConfig prior to 3.1.13 makes it possible to include arbitrary files, leading to code execution. This is exploitable by authenticated users who have local filesystem access.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

ispconfig ispconfig