CVE-2023-46818
About
An issue was discovered in ISPConfig before 3.2.11p1. PHP code injection can be achieved in the language file editor by an admin if admin_allow_langedit is enabled.
Rainforest analyst review
ISPConfig before 3.2.11p1 allows PHP code injection through its language file editor, but two conditions frame it precisely: the actor must be an administrator, and the admin_allow_langedit option has to be enabled. When both hold, an admin can inject PHP that the server executes — code execution on the hosting control panel, which is a powerful position. But the bug is gated by admin privilege and a specific configuration toggle.
That gating is why we rank it below the unauthenticated RCEs it superficially resembles. The realistic threat model is an admin whose credentials were compromised, or a multi-admin panel where not every administrator is fully trusted; it is not something an anonymous internet scanner turns into a shell. The language-editor feature has to be switched on for the path to exist at all, which narrows the exposed population further.
Our practical move is configuration triage rather than a blanket patch scramble: find ISPConfig instances below 3.2.11p1 and check whether admin_allow_langedit is actually enabled, because instances with it off aren't reachable through this path. Where it's on, we prioritize the upgrade and, in the meantime, disabling the setting is a clean interim mitigation that closes the door without waiting.
References
Related CVEs
Frequently asked questions
What is CVE-2023-46818?
An issue was discovered in ISPConfig before 3.2.11p1. PHP code injection can be achieved in the language file editor by an admin if admin_allow_langedit is enabled.
How severe is CVE-2023-46818?
CVE-2023-46818 carries a CVSS 3.1 base score of 7.2, rated high. On the Rainforest Risk Index — which weighs the severity alongside how easy the flaw is to reach and how broad its impact is — it scores 76 out of 100, in the high band.
How is CVE-2023-46818 exploited?
According to the CVSS vector (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H): attack vector Network, attack complexity Low, privileges required High, user interaction None. Impact on confidentiality High, integrity High and availability High.
Which products are affected by CVE-2023-46818?
Public advisories list the following as affected: ispconfig. Check the references on this page for the exact versions each vendor confirms.
How do I fix CVE-2023-46818?
Apply the fix the vendor published — the references on this page link to the primary advisories and patches. When patching can't happen right away, reduce the exposure of the affected component and watch it for exploitation attempts. Rainforest customers see this vulnerability correlated to their own assets and prioritized by real exposure, not by score alone.
Empower Your Security Strategy with Rainforest
Discover vulnerabilities early, prioritize critical threats, and protect what truly matters. Rainforest streamlines your security operations, saving you time and reducing costs, so you can focus on what drives your business forward.
