Impact
Plesk’s Backup Manager contains a path traversal flaw that allows an authenticated customer to write an arbitrary file to any location on the server with root privileges. This vulnerability can be leveraged to replace critical system files, plant malicious scripts, or otherwise take full control of the affected system, effectively giving an attacker remote code execution capabilities.
Affected Systems
The flaw affects Plesk installations from WebPros. The exact versions affected were not detailed in the advisory, so all current and older releases should be considered vulnerable until a patch is applied.
Risk and Exploitability
The CVSS score of 9.9 marks this as critical, and although the EPSS score is unavailable, the high magnitude indicates a serious threat. The attack requires authentication as a customer, but once authenticated it can result in root-level file writes, making exploitation highly valuable to attackers. The vulnerability is not listed in the CISA KEV catalog, but its severity warrants immediate mitigation.
OpenCVE Enrichment