CVE-2025-49618: Medium severity Plesk Obsidian vulnerability
Published Jul 3, 2025
·Updated
In Plesk Obsidian 18.0.69, unauthenticated requests to /loginup.php can reveal an AWS accessKeyId, secretAccessKey, region, and endpoint.
Affected Software
1 affected component
Plesk Obsidian
Event History
Jul 3, 2025
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·01:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2025-49618?
CVE-2025-49618 is considered a high-severity vulnerability due to the exposure of sensitive AWS credentials.
2
How do I fix CVE-2025-49618?
To mitigate CVE-2025-49618, ensure that Plesk Obsidian is updated to the latest version that addresses the vulnerability.
3
What information is exposed in CVE-2025-49618?
CVE-2025-49618 can expose AWS accessKeyId, secretAccessKey, region, and endpoint through unauthenticated requests.
4
Which versions of Plesk Obsidian are affected by CVE-2025-49618?
Plesk Obsidian version 18.0.69 is specifically affected by CVE-2025-49618.
5
Can CVE-2025-49618 be exploited remotely?
Yes, CVE-2025-49618 can be exploited remotely through unauthenticated requests to the vulnerable endpoint.