Impact
This vulnerability is a weakness that allows improper disclosure of cleartext FTP passwords because ownership checks are applied only to specific lookup filters and schema validation is skipped for legacy protocol versions. An authenticated customer with low privileges can therefore request domain information that belongs to other tenants, exposing FTP credentials stored in cleartext. Those credentials can be used to run code as another tenant’s system user, compromising both confidentiality and integrity.
Affected Systems
WebPros Plesk instances running any version earlier than 18.0.78.4 are affected. The flaw applies to all tenants that use the legacy XML‑RPC protocol and allows them to read domain data they do not own.
Risk and Exploitability
The CVSS score of 9.9 categorises the issue as Critical, indicating a high potential impact if exploited. The EPSS score is less than 1 %, suggesting that exploitation attempts are infrequent. The vulnerability is not listed in CISA KEV. A likely attack vector involves a low‑privileged authenticated customer logging into the Plesk control panel, sending a legacy XML‑RPC request that bypasses schema validation, harvesting exposed FTP credentials, and then using those credentials to execute code as the system user of another tenant.
OpenCVE Enrichment