Loading
ISPConfig before 3.1.15p3, when the undocumented reverse_proxy_panel_allowed=sites option is manually enabled, allows SQL Injection.
Cite this page
CVE-2020-9398. CVEDatabase.com. Retrieved 1 May 2026. https://cvedatabase.com/cve/CVE-2020-9398
Use CWE-89, Ispconfig vendor hub and Ispconfig product page to widen CVE-2020-9398 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2021-3021, CVE-2012-2087 and CVE-2013-3629 for nearby disclosures in the same product family.