Plesk 17.0 through 18.0.31 version, is vulnerable to a Cross-Site Scripting. A malicious subscription owner (either a customer or an additional user), can fully compromise the server if an administrator visits a certain page in Plesk related to the malicious subscription.
Advisories
Source ID Title
EUVD EUVD EUVD-2023-12831 Plesk 17.0 through 18.0.31 version, is vulnerable to a Cross-Site Scripting. A malicious subscription owner (either a customer or an additional user), can fully compromise the server if an administrator visits a certain page in Plesk related to the malicious subscription.
Fixes

Solution

This vulnerability is fixed in the latest supported versions of Plesk.


Workaround

No workaround given by the vendor.

History

Tue, 24 Sep 2024 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


cve-icon MITRE

Status: PUBLISHED

Assigner: INCIBE

Published:

Updated: 2024-09-24T19:03:10.987Z

Reserved: 2023-02-14T13:25:51.618Z

Link: CVE-2023-0829

cve-icon Vulnrichment

Updated: 2024-08-02T05:24:34.417Z

cve-icon NVD

Status : Modified

Published: 2023-09-20T13:15:11.547

Modified: 2024-11-21T07:37:54.817

Link: CVE-2023-0829

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.