CVE-2021-27231: Medium severity hestiacp vulnerability
Hestia Control Panel 1.3.5 and below, in a shared-hosting environment, sometimes allows remote authenticated users to create a subdomain for a different customer's domain name, leading to spoofing of services or email messages.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2021-27231.
What is the severity of CVE-2021-27231?
The severity of CVE-2021-27231 is medium with a CVSS score of 5.4.
How does CVE-2021-27231 affect Hestia Control Panel?
CVE-2021-27231 affects Hestia Control Panel versions 1.3.5 and below in a shared-hosting environment.
What is the impact of CVE-2021-27231?
CVE-2021-27231 allows remote authenticated users to create a subdomain for a different customer's domain name, which can lead to spoofing of services or email messages.
Are there any known fixes or mitigation steps for CVE-2021-27231?
Currently, there are no known fixes or mitigation steps available for CVE-2021-27231. It is recommended to monitor the official sources for any updates or patches.