{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/ispconfig--3.2.11/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:ispconfig:ispconfig:*:*:*:*:*:*:*:*","cpe:2.3:a:ispconfig:ispconfig:3.2.11:-:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7.2,"id":"CVE-2023-46818"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["ISPConfig (\u003c 3.2.11)"],"_cs_severities":["high"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["ISPConfig"],"content_html":"\u003cp\u003eCVE-2023-46818 is a PHP code injection vulnerability impacting ISPConfig versions 3.2.11 and earlier. The vulnerability exists within the 'language_edit.php' script, which fails to properly sanitize the 'records[]' form field input. By leveraging high-privileged administrative credentials, an attacker can submit malicious PHP code through this parameter, leading to arbitrary code execution on the underlying server.\u003c/p\u003e\n\u003cp\u003eAs of August 2026, proof-of-concept exploit code has been published and is actively circulating, significantly lowering the barrier for exploitation. The released exploit automates the authentication process, performs the code injection to drop a persistent 'sh.php' web shell, and establishes an interactive interface for remote command execution. Defenders should prioritize patching ISPConfig installations to versions beyond 3.2.11 and auditing administrative access logs for suspicious activity targeting language management endpoints.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker obtains or possesses valid administrative credentials for the ISPConfig management panel.\u003c/li\u003e\n\u003cli\u003eAttacker authenticates to the ISPConfig interface using the compromised high-privileged account.\u003c/li\u003e\n\u003cli\u003eAttacker navigates to the language management functionality, specifically interacting with 'language_edit.php'.\u003c/li\u003e\n\u003cli\u003eAttacker submits a POST request to 'language_edit.php' containing the malicious payload within the 'records[]' form field.\u003c/li\u003e\n\u003cli\u003eThe server-side PHP script evaluates the injected payload, causing the creation of a malicious file, typically 'sh.php', on the file system.\u003c/li\u003e\n\u003cli\u003eThe attacker interacts with the newly created 'sh.php' web shell to issue OS-level commands.\u003c/li\u003e\n\u003cli\u003eThe web shell executes the commands and returns the output to the attacker, often delimited by custom markers.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation results in full Remote Code Execution (RCE) on the ISPConfig host. An attacker can use this access to exfiltrate sensitive data, manipulate server configurations, or pivot to internal network segments. Given the nature of ISPConfig as a hosting control panel, a compromise likely impacts all hosted websites, databases, and mail services managed by the application.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003ePatch all ISPConfig instances to a version later than 3.2.11 immediately.\u003c/li\u003e\n\u003cli\u003eDeploy the provided Sigma rule to detect POST requests to 'language_edit.php' containing suspicious characters associated with injection.\u003c/li\u003e\n\u003cli\u003eAudit web server access logs for requests to 'sh.php' or other unexpected script files within the web root.\u003c/li\u003e\n\u003cli\u003eRestrict access to the ISPConfig administrative panel to known-safe IP addresses using network-layer controls.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-31T17:05:03Z","date_published":"2026-08-31T17:05:03Z","id":"https://feed.craftedsignal.io/briefs/2026-08-cve-2023-46818-exploit/","summary":"A functional exploit for CVE-2023-46818 in ISPConfig allows authenticated high-privileged users to achieve Remote Code Execution via PHP code injection in language_edit.php.","title":"Public Exploit Released for ISPConfig PHP Code Injection (CVE-2023-46818)","url":"https://feed.craftedsignal.io/briefs/2026-08-cve-2023-46818-exploit/"}],"language":"en","title":"CraftedSignal Threat Feed - ISPConfig (\u003c 3.2.11)","version":"https://jsonfeed.org/version/1.1"}