A Host Header Injection issue on the Login page of Plesk Obsidian through 18.0.49 allows attackers to redirect users to malicious websites via a Host request header. NOTE: the vendor's position is "the ability to use arbitrary domain names to access the panel is an intended feature."
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Wed, 02 Apr 2025 16:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2025-04-02T15:49:05.161Z

Reserved: 2023-01-21T00:00:00.000Z

Link: CVE-2023-24044

cve-icon Vulnrichment

Updated: 2024-08-02T10:49:08.809Z

cve-icon NVD

Status : Modified

Published: 2023-01-22T03:15:09.967

Modified: 2025-04-02T16:15:33.697

Link: CVE-2023-24044

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.