CVE-2020-10966: Medium severity hestiacp vulnerability
In the Password Reset Module in VESTA Control Panel through 0.9.8-25 and Hestia Control Panel before 1.1.1, Host header manipulation leads to account takeover because the victim receives a reset URL containing an attacker-controlled server name.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2020-10966?
CVE-2020-10966 is a vulnerability in the Password Reset Module in VESTA Control Panel through 0.9.8-25 and Hestia Control Panel before 1.1.1.
How does CVE-2020-10966 affect VESTA Control Panel?
CVE-2020-10966 can lead to account takeover in VESTA Control Panel versions up to 0.9.8-25.
How does CVE-2020-10966 affect Hestia Control Panel?
CVE-2020-10966 can lead to account takeover in Hestia Control Panel versions before 1.1.1.
What is the severity of CVE-2020-10966?
CVE-2020-10966 has a severity rating of 6.5 (Medium).
How can CVE-2020-10966 be fixed?
To fix CVE-2020-10966, users should update VESTA Control Panel to version 0.9.8-26 or newer, and Hestia Control Panel to version 1.1.1 or newer.