myVesta Control Panel before 0.9.8-26-43 and Vesta Control Panel before 0.9.8-26 are vulnerable to command injection. An authenticated and remote administrative user can execute arbitrary commands via the v_sftp_license parameter when sending HTTP POST requests to the /edit/server endpoint.
Subscriptions
Tracking
Sign in to view the affected projects.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Wed, 07 May 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2025-05-07T14:29:33.754Z
Reserved: 2022-10-24T00:00:00.000Z
Link: CVE-2021-46850
Updated: 2024-08-04T05:17:42.463Z
Status : Modified
Published: 2022-10-24T14:15:50.067
Modified: 2025-05-07T15:15:52.560
Link: CVE-2021-46850
No data.
OpenCVE Enrichment
No data.
Weaknesses