Ispconfig · Ispconfig · CVE-2018-17984
**Name of the Vulnerable Software and Affected Versions**
ISPConfig versions prior to 3.1.13
**Description**
The issue is related to an unanchored regular expression in the software, which allows authenticated users with local filesystem access to include arbitrary files. This can lead to code execution.
**Recommendations**
For versions prior to 3.1.13, update to version 3.1.13 or later to resolve the issue.