Loading
An unanchored /[a-z]{2}/ regular expression in ISPConfig before 3.1.13 makes it possible to include arbitrary files, leading to code execution. This is exploitable by authenticated users who have local filesystem access.
Cite this page
CVE-2018-17984. CVEDatabase.com. Retrieved 1 May 2026. https://cvedatabase.com/cve/CVE-2018-17984
Use CWE-185, Ispconfig vendor hub and Ispconfig product page to widen CVE-2018-17984 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2021-3021, CVE-2020-9398 and CVE-2012-2087 for nearby disclosures in the same product family.