Impact
An SQL injection flaw in WebPros: Plesk Obsidian allows an authenticated user to read any data stored in the control panel database. The vulnerability is a classic injection weakness (CWE‑89) that can expose confidential configuration and user information, thereby undermining the confidentiality of the entire hosting environment. The impact is limited to data disclosure, not code execution or denial of service. Based on the description, the primary attack vector is an authenticated session, so attackers need valid credentials but can then issue arbitrary queries to the database.
Affected Systems
The flaw applies to WebPros: Plesk Obsidian versions up to 18.0.80 running on Linux and Windows. Any installations of these versions that have at least one authenticated user account are potentially affected. Upgrading beyond 18.0.80 removes the vulnerability.
Risk and Exploitability
The CVSS score of 7.7 classifies this as high‑severity. The EPSS score has not been published, so the current likelihood of exploitation is unclear. The vulnerability is not listed in CISA’s KEV catalog. Because the issue requires authentication, the risk is mitigated to users who possess credentials; however, once an attacker gains such credentials—through phishing, credential stuffing, or other means—they can read arbitrary data from the panel database, posing a serious confidentiality risk.
OpenCVE Enrichment