ISPConfig Vulnerability Allows Privilege Escalation to Superadmin and PHP Code Injection

A critical security vulnerability has been discovered in ISPConfig version 3.2 build 12p1 that allows authenticated remote users to escalate their privileges to superadmin status and subsequently execute arbitrary PHP code on affected systems.  The vulnerability, identified by an independent security researcher working with SSD Secure Disclosure, exploits design flaws in the user creation and […]

The post ISPConfig Vulnerability Allows Privilege Escalation to Superadmin and PHP Code Injection appeared first on Cyber Security News.

This article has been indexed from Cyber Security News

Read the original article: