ISPConfig 3.x before 3.1.9 allows remote authenticated users to obtain root access by creating a crafted cron job.
The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.
Link | Tags |
---|---|
https://www.ispconfig.org/blog/ispconfig-3-1-9-released-important-security-update/ | patch vendor advisory issue tracking |