CVE-2018-18547: XSS
Vesta Control Panel through 0.9.8-22 has XSS via the edit/web/ domain parameter, the list/backup/ backup parameter, the list/rrd/ period parameter, the list/directory/ dira parameter, or the filename to the list/directory/ URI.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2018-18547?
The severity of CVE-2018-18547 is medium with a severity score of 6.1.
How does CVE-2018-18547 impact Vesta Control Panel?
CVE-2018-18547 allows for cross-site scripting (XSS) attacks via several parameters in Vesta Control Panel, including the edit/web/ domain parameter, the list/backup/ backup parameter, the list/rrd/ period parameter, the list/directory/ dir_a parameter, or the filename to the list/directory/ URI.
Can an attacker exploit CVE-2018-18547 remotely?
Yes, an attacker can remotely exploit CVE-2018-18547.
Is there a fix available for CVE-2018-18547?
Yes, updating to Vesta Control Panel version 0.9.8-23 or later fixes CVE-2018-18547.
Are there any known public exploits for CVE-2018-18547?
Yes, there are known public exploits for CVE-2018-18547. It is recommended to update to the latest version of Vesta Control Panel to mitigate the vulnerability.