First published: Sun Jan 22 2023(Updated: )
** DISPUTED ** A Host Header Injection issue on the Login page of Plesk Obsidian through 18.0.49 allows attackers to redirect users to malicious websites via a Host request header. NOTE: the vendor's position is "the ability to use arbitrary domain names to access the panel is an intended feature."
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Plesk | <=18.0.49 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2023-24044.
The severity of CVE-2023-24044 is medium.
CVE-2023-24044 affects Plesk Obsidian versions up to and including 18.0.49.
An attacker can redirect users to malicious websites via a Host request header.
The vendor considers the ability to use arbitrary domain names to access the panel as an intended feature.