CVE-2023-0829: Cross-Site Scripting (XSS) vulnerability in Plesk
Plesk 17.0 through 18.0.31 version, is vulnerable to a Cross-Site Scripting. A malicious subscription owner (either a customer or an additional user), can fully compromise the server if an administrator visits a certain page in Plesk related to the malicious subscription.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is CVE-2023-0829?
CVE-2023-0829 is a Cross-Site Scripting vulnerability in Plesk 17.0 through 18.0.31 version.
How does CVE-2023-0829 impact Plesk?
CVE-2023-0829 allows a malicious subscription owner to fully compromise the server by exploiting a certain page in Plesk.
What is the severity of CVE-2023-0829?
CVE-2023-0829 has a severity level of critical.
How can an attacker exploit CVE-2023-0829?
An attacker can exploit CVE-2023-0829 by creating a malicious subscription in Plesk and tricking an administrator into visiting a certain page related to the subscription.
Is there a fix available for CVE-2023-0829?
Yes, upgrading to a version of Plesk that is after 18.0.31 can fix the CVE-2023-0829 vulnerability.