CVE-2023-24044: Medium severity plesk vulnerability
Published Jan 22, 2023
·Updated
DISPUTED A Host Header Injection issue on the Login page of Plesk Obsidian through 18.0.49 allows attackers to redirect users to malicious websites via a Host request header. NOTE: the vendor's position is "the ability to use arbitrary domain names to access the panel is an intended feature."
Affected Software
1 affected component
Plesk Obsidian<=18.0.49
Event History
Jan 22, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Disputed
03:15 AM
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
The vulnerability ID is CVE-2023-24044.
2
What is the severity of CVE-2023-24044?
The severity of CVE-2023-24044 is medium.
3
How does CVE-2023-24044 affect Plesk Obsidian?
CVE-2023-24044 affects Plesk Obsidian versions up to and including 18.0.49.
4
What can an attacker do with CVE-2023-24044?
An attacker can redirect users to malicious websites via a Host request header.
5
Is CVE-2023-24044 a legitimate vulnerability?
The vendor considers the ability to use arbitrary domain names to access the panel as an intended feature.