SQL Injection Vulnerability in ISPConfig by ISPConfig
CVE-2020-9398
9.8CRITICAL
What is CVE-2020-9398?
An SQL injection vulnerability exists in ISPConfig versions before 3.1.15p3, triggered when the undocumented 'reverse_proxy_panel_allowed=sites' option is manually enabled. This flaw allows attackers to execute arbitrary SQL commands, potentially compromising the integrity and confidentiality of the database.