Impact
A flaw in Plesk’s DNS zone management service fails to neutralize special elements in user input, enabling an authenticated user to read arbitrary local files from the server and, because of improper sanitization, potentially inject and execute operating‑system commands. This vulnerability aligns with CWE‑74 (Improper Neutralization of Input) and CWE‑78 (OS Command Injection). The direct consequences are local file disclosure and privilege escalation within the Plesk environment.
Affected Systems
The issue affects all installations of the WebPros Plesk control panel that include the DNS zone management feature. No specific version is mentioned in the advisory, so the risk applies to any Plesk version until a vendor release addresses the flaw.
Risk and Exploitability
The flaw is assigned a CVSS base score of 8.7, indicating high severity. The EPSS score of less than 1% suggests a low probability of exploitation at present, and the vulnerability is not listed in CISA’s KEV catalog. Exploitation requires valid credentials with DNS zone management permissions, and the attack vector is remote, performed over the network. Because the flaw enables both file disclosure and privilege escalation, it poses a considerable threat if an authenticated user already has privileged access or can expand privileges.
OpenCVE Enrichment