ISPConfig
cpe:2.3:a:ispconfig:ispconfig:*:*:*:*:*:*:*
- 3.3.0
A cross-site scripting (XSS) vulnerability has been identified in ISPConfig version 3.3.0. This issue arises on the system status webpage, where user input is not properly sanitized, allowing for the injection of malicious scripts.
Exploitation of this vulnerability allows for authenticated reflected cross-site scripting, where an attacker can inject malicious scripts that are executed in the context of the user's browser.
Users can update to ISPConfig 3.3.0p2, which addresses this vulnerability. The update can be performed using the ispconfig_update.sh command or manually by downloading the update from the ISPConfig website and running the provided installation commands.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.