Skip to content

Authenticated XSS issue in email forms and DNS zone import tool

Reflected XSS issues have been found in the forms of the ISPConfig mail module. A stored XSS issue has been found in the DNS zone import tool.

All XSS issues require a valid login as client, reseller, or administrator.

Thank you to Dogus Demirkiran (BEND0US) for reporting the issues to us.