CVE-2019-12792: OS Command Injection
Published Aug 15, 2019
·Updated
A command injection vulnerability in UploadHandler.php in Vesta Control Panel 0.9.8-24 allows remote attackers to escalate from regular registered users to root.
Affected Software
1 affected component
VestaCP Control Panel=0.9.8-24
Event History
Aug 15, 2019
CVE Published
via MITRE·08:39 PM
Data Sourced
via MITRE·08:39 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID?
The vulnerability ID is CVE-2019-12792.
2
What is the severity of CVE-2019-12792?
The severity of CVE-2019-12792 is critical with a severity value of 8.8.
3
What is the affected software?
The affected software is Vesta Control Panel version 0.9.8-24.
4
How does CVE-2019-12792 impact the system?
CVE-2019-12792 allows remote attackers to escalate from regular registered users to root.
5
Are there any references related to CVE-2019-12792?
Yes, there are references related to CVE-2019-12792. You can find them at the following links: [Link 1](https://cardaci.xyz/advisories/2019/08/12/vesta-control-panel-0.9.8-24-privilege-escalation-in-the-upload-handler/) and [Link 2](https://github.com/serghey-rodin/vesta/issues/1921).