CVE-2021-30463: High severity vesta control panel vulnerability
VestaCP through 0.9.8-24 allows attackers to gain privileges by creating symlinks to files for which they lack permissions. After reading the RKEY value from user.conf under the /usr/local/vesta/data/users/admin directory, the admin password can be changed via a /reset/?action=confirm&user=admin&code= URI. This occurs because chmod is used unsafely.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID?
The vulnerability ID is CVE-2021-30463.
What is the severity of CVE-2021-30463?
The severity of CVE-2021-30463 is high with a severity value of 7.8.
What is the affected software of CVE-2021-30463?
The affected software of CVE-2021-30463 is VestaCP control panel version 0.9.8-24.
How can attackers exploit CVE-2021-30463?
Attackers can exploit CVE-2021-30463 by creating symlinks to files for which they lack permissions and changing the admin password.
Is there a fix for CVE-2021-30463?
A fix for CVE-2021-30463 may be available from the vendor. It is recommended to update to the latest version of VestaCP to mitigate this vulnerability.