CVE-2020-9398: SQL Injection
ISPConfig before 3.1.15p3, when the undocumented reverseproxypanelallowed=sites option is manually enabled, allows SQL Injection.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
ISPConfigto a version that resolves this vulnerability.Fixed in 3.1.15p3 - Configuration
Do not manually enable the undocumented reverse_proxy_panel_allowed=sites option; remove/disable this manual setting to prevent SQL Injection exposure in ISPConfig versions before 3.1.15p3.
ISPConfig reverse_proxy_panel_allowed option reverse_proxy_panel_allowed = sites
Event History
Frequently Asked Questions
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2020-9398.
What is the severity of CVE-2020-9398?
The severity of CVE-2020-9398 is critical with a CVSS score of 9.8.
What is the affected software?
The affected software is ISPConfig before 3.1.15p3.
How can the SQL Injection be exploited?
The SQL Injection can be exploited when the undocumented reverse_proxy_panel_allowed=sites option is manually enabled.
How can the vulnerability be fixed?
The vulnerability can be fixed by upgrading to ISPConfig version 3.1.15p3.