Skip to content

Language file importer does not check file names properly

A system administrator (superuser) can upload language files that he exported from ISPConfig to keep custom translations. The languge file upload does not check file endings of the files it creates properly. The function is available only to the super admin (admin user id 1), so any potential misuse of the language file restore function would require a valid admin login to the system.

Thank you to Dogus Demirkiran (BEND0US) for reporting the issue to us.

Edited by Till Brehm