Back to Database
Status published
Critical
CVE-2021-3021
ISPConfig before 3.2.2 allows SQL injection....
Vulnerability Description
ISPConfig before 3.2.2 allows SQL injection.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2021-3021
Credits & Attribution
No credits recorded in the NVD database.
References
More from ispconfig
View All →CVE-2020-9398
ISPConfig before 3.1.15p3, when the undocumented reverse_proxy_panel_allowed=sites option is manually...
Critical
9.8
CVE-2018-17984
An unanchored /[a-z]{2}/ regular expression in ISPConfig before 3.1.13 makes...
High
7.8
CVE-2017-17384
ISPConfig 3.x before 3.1.9 allows remote authenticated users to obtain...
High
8.8
CVE-2015-4119
Multiple cross-site request forgery (CSRF) vulnerabilities in ISPConfig before 3.0.5.4p7...
Medium
6.8
CVE-2015-4118
SQL injection vulnerability in monitor/show_sys_state.php in ISPConfig before 3.0.5.4p7 allows...
Medium
6.5
Affected Vendor
ispconfig
View all reports →Affected Software
ispconfig
Vulnerable Versions:
0
Timeline
Official Publish:
January 5th, 2021
Last Modified:
August 3rd, 2024
Added to House:
July 21st, 2026
CVSS Vectors
V3:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.