CVE-2021-46850: Command Injection
Published Oct 24, 2022
·Updated
myVesta Control Panel before 0.9.8-26-43 and Vesta Control Panel before 0.9.8-26 are vulnerable to command injection. An authenticated and remote administrative user can execute arbitrary commands via the vsftplicense parameter when sending HTTP POST requests to the /edit/server endpoint.
Affected Software
2 affected components
VestaCP Control Panel<0.9.8-26-43
VestaCP Vesta Control Panel<0.9.8-26
Remediation
Event History
Oct 24, 2022
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·02:15 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2021-46850.
2
What is the severity of CVE-2021-46850?
The severity of CVE-2021-46850 is high with a severity value of 7.2.
3
Which versions of myVesta Control Panel are affected by CVE-2021-46850?
Versions of myVesta Control Panel before 0.9.8-26-43 are affected by CVE-2021-46850.
4
Which versions of Vesta Control Panel are affected by CVE-2021-46850?
Versions of Vesta Control Panel before 0.9.8-26 are affected by CVE-2021-46850.
5
How does the vulnerability in myVesta Control Panel and Vesta Control Panel manifest?
The vulnerability in myVesta Control Panel and Vesta Control Panel manifests as a command injection vulnerability.