First published: Wed Nov 13 2019(Updated: )
Parallels Plesk Panel 9.5 allows XSS in target/locales/tr-TR/help/index.htm? via the "fileName" parameter.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Plesk | =9.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-18793 is classified as a medium-severity vulnerability due to its potential for cross-site scripting (XSS) attacks.
To fix CVE-2019-18793, update Parallels Plesk Panel to the latest version that addresses this XSS vulnerability.
CVE-2019-18793 allows attackers to execute arbitrary JavaScript in the context of a user's session, potentially compromising user data and session integrity.
CVE-2019-18793 specifically affects Parallels Plesk Panel version 9.5.
While updating to a patched version is the best solution, users can also implement input validation to mitigate the effects of CVE-2019-18793.