Impact
Based on the description, the vulnerability resides in Plesk’s Backup Manager component, where an authenticated customer can exploit a path traversal flaw in the upload process to write an arbitrary file anywhere on the host as root. The description indicates that the flaw may enable replacement of critical system files or injection of malicious payloads, which could compromise system integrity and potentially lead to full system compromise.
Affected Systems
All WebPros Plesk installations are affected, but the data does not specify which versions are vulnerable; affected version ranges are unavailable.
Risk and Exploitability
Based on the description, an attacker who is an authenticated customer may write an arbitrary file as root. With a CVSS score of 9.9 the flaw is critical. The EPSS score is not available and the vulnerability is not listed in the CISA KEV catalog, but the severity remains high because the attacker only needs valid customer credentials to exercise unlimited file system write access as root; this high privilege level makes the vulnerability an attractive target for threat actors.
OpenCVE Enrichment