CVE-2020-10787: Critical severity VestaCP Vesta Control Panel vulnerability
An elevation of privilege in Vesta Control Panel through 0.9.8-26 allows an attacker to gain root system access from the admin account via v-change-user-password (aka the user password change script).
Affected Software
Event History
Frequently Asked Questions
What is CVE-2020-10787?
CVE-2020-10787 is a vulnerability in Vesta Control Panel through version 0.9.8-26 that allows an attacker to gain root system access from the admin account via the user password change script.
How severe is CVE-2020-10787?
CVE-2020-10787 has a severity rating of 8.8 (critical).
How can an attacker exploit CVE-2020-10787?
An attacker can exploit CVE-2020-10787 by using the v-change-user-password script in Vesta Control Panel to gain root system access from the admin account.
Which version of Vesta Control Panel is affected by CVE-2020-10787?
Vesta Control Panel versions up to and including 0.9.8-26 are affected by CVE-2020-10787.
Is there a fix for CVE-2020-10787?
Yes, updating Vesta Control Panel to a version beyond 0.9.8-26 will fix the vulnerability.