Impact
HestiaCP releases older than 1.9.5 contain a stored cross‑site scripting flaw that allows an authenticated low‑privilege user to inject arbitrary HTML into a DNS record value field. The application fails to apply htmlspecialchars() encoding when rendering the value into a data‑sort‑value attribute in list_dns_rec.php, permitting a script payload to execute inside the browser of any user who views the DNS record list, including administrators.
Affected Systems
The vulnerable product is Hestia Control Panel (HestiaCP) provided by Hestiacp. All releases prior to version 1.9.5 are affected; no other sub‑components are listed in the advisory.
Risk and Exploitability
The CVSS score of 5.1 classifies the vulnerability as moderate. Exploitation requires an authenticated session with permission to create or edit DNS records, a capability typically granted to low‑privilege accounts. The attack vector is inferred to be web‑application based on the description. The EPSS score is less than 1%, indicating a low probability of widespread exploitation, and the flaw is not listed in CISA’s KEV catalog.
OpenCVE Enrichment