CVE-2023-46818
HIGH 7.2EPSS 15.9%
An issue was discovered in ISPConfig before 3.2.11p1. PHP code injection can be achieved in the language file editor by an admin if admin_allow_langedit is enabled.
- CVSS v3.1
- 7.2 HIGH
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H - CVSS v3.1
- 7.2 HIGH
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H - EPSS
- 15.86% chance of exploitation in the next 30 days, 97th percentile
- Nuclei
- high · CWE-94
- Published
- 2023-10-27
- Updated
- 2024-10-11
Proof-of-concept exploits (12)
- SyFi/CVE-2023-468180★ · 2025-06-25
- ajdumanhug/CVE-2022-420921★ · 2025-04-27
- ajdumanhug/CVE-2023-4681815★ · 2025-04-16
- bipbopbup/CVE-2023-46818-python-exploit18★ · 2024-10-08
- blindma1den/CVE-2023-46818-Exploit6★ · 2025-04-13
- cuerv0x/CVE_2023_468180★ · 2025-08-17
- engranaabubakar/CVE-2023-468180★ · 2025-05-28
- hunntr/CVE-2023-4681816★ · 2025-07-06
- rvizx/CVE-2023-468184★ · 2025-06-22
- vulnerk0/CVE-2023-468180★ · 2025-08-01
- zs1n/CVE-2023-468181★ · 2025-11-10
- rvzsec/CVE-2023-46818