Product
An authenticated SQL injection vulnerability in the ISPConfig Remote API allows low-privilege users to execute arbitrary queries, leading to unauthorized data exfiltration and cross-tenant record manipulation.