Impact
Improper neutralization of special elements in Plesk's DNS zone management functionality allows remote authenticated users to disclose arbitrary local files and elevate privileges. This means that anyone with DNS zone management rights can read any file on the server and potentially gain higher level permissions, leading to both file disclosure and privilege escalation. The flaw is classified as CWE-74 and CWE-78.
Affected Systems
The issue affects all installations of the WebPros Plesk control panel that include the DNS zone management feature. No specific version Plesk version until a vendor release addresses the flaw.
Risk and Exploitability
The flaw is assigned a CVSS base score of 8.8, indicating high severity. The EPSS score of less than 1% suggests a low probability of exploitation at present, and the vulnerability is not listed in CISA’s KEV catalog. Exploitation requires valid credentials with DNS zone management permissions, and the attack vector is remote, performed over the network. Because the flaw enables both file disclosure and privilege escalation, it benefits an attacker who already has privileged access or can expand privileges.
OpenCVE Enrichment