First published: Tue Apr 21 2020(Updated: )
A remote command execution in Vesta Control Panel through 0.9.8-26 allows any authenticated user to execute arbitrary commands on the system via cron jobs.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Vestacp Vesta Control Panel | <=0.9.8-26 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-10786 is a vulnerability in Vesta Control Panel through 0.9.8-26 that allows any authenticated user to execute arbitrary commands on the system via cron jobs.
The severity of CVE-2020-10786 is critical with a CVSS score of 8.8.
Vesta Control Panel versions up to and including 0.9.8-26 are affected by CVE-2020-10786.
An authenticated user can exploit CVE-2020-10786 by executing arbitrary commands on the system through cron jobs.
Yes, updating Vesta Control Panel to a version later than 0.9.8-26 fixes CVE-2020-10786.