← Vulnerability feed

Vulnerability record · CVE-2021-3021 · published 5 January 2021

CVE-2021-3021: Ispconfig sql injection vulnerability

Ispconfig · Ispconfig

ISPConfig before 3.2.2 allows SQL injection.

9.8 CVSS 3.1 Critical EPSS 2.1% · top 18.9% CWE-89 · SQL injection
9.8CVSS 3.1 base score, v2 7.5
2.1%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
4References
17 Jun 2026Last modified by NVD

Description

ISPConfig before 3.2.2 allows SQL injection.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2021-3021 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2020-9398Ispconfig sql injection vulnerabilityISPConfig before 3.1.15p3, when the undocumented reverse_proxy_panel_allowed=sites option is manually enabled, allows SQL Injection.EPSS 1.3%9.8CVE-2012-2087Ispconfig incorrect permission assignment vulnerabilityISPConfig 3.0.4.3: the "Add new Webdav user" can chmod and chown entire server from client interface.EPSS 2.7%8.8CVE-2013-3629Ispconfig vulnerabilityISPConfig 3.0.5.2 has Arbitrary PHP Code ExecutionEPSS 43%8.8CVE-2017-17384Ispconfig improper privilege management vulnerabilityISPConfig 3.x before 3.1.9 allows remote authenticated users to obtain root access by creating a crafted cron job.EPSS 1.5%7.8CVE-2018-17984Ispconfig vulnerabilityAn unanchored /[a-z]{2}/ regular expression in ISPConfig before 3.1.13 makes it possible to include arbitrary files, leading to code execution. This …EPSS 3.4%7.5CVE-2006-3042Ispconfig vulnerabilityMultiple PHP remote file inclusion vulnerabilities in ISPConfig 2.2.3 allow remote attackers to execute arbitrary PHP code via a URL in the (1) go_in…EPSS 2.9%7.5CVE-2006-2315Ispconfig code injection vulnerabilityPHP remote file inclusion vulnerability in session.inc.php in ISPConfig 2.2.2 and earlier allows remote attackers to execute arbitrary PHP code via a…EPSS 4.8%7.2CVE-2023-46818Ispconfig code injection vulnerabilityAn issue was discovered in ISPConfig before 3.2.11p1. PHP code injection can be achieved in the language file editor by an admin if admin_allow_lange…EPSS 16%

Source: NIST National Vulnerability Database (record CVE-2021-3021), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.