CVE-2019-12791: Path Traversal
A directory traversal vulnerability in the v-list-user script in Vesta Control Panel 0.9.8-24 allows remote attackers to escalate from regular registered users to root via the password reset form.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2019-12791?
CVE-2019-12791 is a directory traversal vulnerability in the v-list-user script in Vesta Control Panel 0.9.8-24 that allows remote attackers to escalate from regular registered users to root via the password reset form.
How severe is CVE-2019-12791?
CVE-2019-12791 has a severity rating of 8.8 (Critical).
How can I fix CVE-2019-12791?
To fix CVE-2019-12791, you should update to a version of Vesta Control Panel that is not affected by this vulnerability.
Where can I find more information about CVE-2019-12791?
You can find more information about CVE-2019-12791 at the following references: [Advisory](https://cardaci.xyz/advisories/2019/08/12/vesta-control-panel-0.9.8-24-privilege-escalation-in-the-password-reset-form/) and [GitHub Issue](https://github.com/serghey-rodin/vesta/issues/1921).
What is CWE-22?
CWE-22 is a common weakness enumeration for Path Traversal vulnerabilities.