An unanchored /[a-z]{2}/ regular expression in ISPConfig before 3.1.13 makes it possible to include arbitrary files, leading to code execution. This is exploitable by authenticated users who have local filesystem access.
The product specifies a regular expression in a way that causes data to be improperly matched or compared.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Ispconfig | Ispconfig | * | 3.1.13 (excluding) |