Description
Plesk 17.0 through 18.0.31 version, is vulnerable to a Cross-Site Scripting. A malicious subscription owner (either a customer or an additional user), can fully compromise the server if an administrator visits a certain page in Plesk related to the malicious subscription.
No analysis available yet.
Remediation
Vendor Solution
This vulnerability is fixed in the latest supported versions of Plesk.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-12831 | Plesk 17.0 through 18.0.31 version, is vulnerable to a Cross-Site Scripting. A malicious subscription owner (either a customer or an additional user), can fully compromise the server if an administrator visits a certain page in Plesk related to the malicious subscription. |
References
History
Tue, 24 Sep 2024 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: INCIBE
Published:
Updated: 2024-09-24T19:03:10.987Z
Reserved: 2023-02-14T13:25:51.618Z
Link: CVE-2023-0829
Updated: 2024-08-02T05:24:34.417Z
Status : Modified
Published: 2023-09-20T13:15:11.547
Modified: 2024-11-21T07:37:54.817
Link: CVE-2023-0829
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD