Impact
An insecure direct object reference exists in the Plesk database management interface. The flaw permits any remote user that has authenticated to the Plesk control panel to read or modify databases belonging to other customers. The result is a confidentiality breach and potential data loss for those other customers. The weakness is categorized as CWE‑639.
Affected Systems
Plesk by WebPros – specifically versions 18.0.79.7 and earlier, and the release series 18.0.80 through 18.0.80.3 are vulnerable. Systems running these releases are at risk if the database management interface is exposed to remote users.
Risk and Exploitability
The CVSS score of 8.6 marks this vulnerability as high severity. The EPSS score is not available, but the lack of a KEV listing does not diminish the risk; the flaw can be exploited by any authenticated Plesk user over the network. If an attacker has credentials for a customer account, they can target other customers’ databases directly, leading to unauthorized disclosure or alteration. "
OpenCVE Enrichment