First published: Wed Sep 20 2023(Updated: )
Plesk 17.0 through 18.0.31 version, is vulnerable to a Cross-Site Scripting. A malicious subscription owner (either a customer or an additional user), can fully compromise the server if an administrator visits a certain page in Plesk related to the malicious subscription.
Credit: cve-coordination@incibe.es
Affected Software | Affected Version | How to fix |
---|---|---|
Plesk Obsidian | >=17.0<=18.0.31 |
This vulnerability is fixed in the latest supported versions of Plesk.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-0829 is a Cross-Site Scripting vulnerability in Plesk 17.0 through 18.0.31 version.
CVE-2023-0829 allows a malicious subscription owner to fully compromise the server by exploiting a certain page in Plesk.
CVE-2023-0829 has a severity level of critical.
An attacker can exploit CVE-2023-0829 by creating a malicious subscription in Plesk and tricking an administrator into visiting a certain page related to the subscription.
Yes, upgrading to a version of Plesk that is after 18.0.31 can fix the CVE-2023-0829 vulnerability.