CVE-2025-65518: High severity Plesk Obsidian vulnerability
Plesk Obsidian versions 8.0.1 through 18.0.73 are vulnerable to a Denial of Service (DoS) condition. The vulnerability exists in the getpassword.php endpoint, where a crafted request containing a malicious payload can cause the affected web interface to continuously reload, rendering the service unavailable to legitimate users. An attacker can exploit this issue remotely without authentication, resulting in a persistent availability impact on the affected Plesk Obsidian instance.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Plesk Obsidianto a version that resolves this vulnerability.Fixed in 18.0.73 - Compensating control
Mitigate the DoS against the vulnerable get_password.php endpoint in the Plesk Obsidian web interface by blocking or filtering requests to get_password.php (e.g., via WAF/reverse proxy rules) until the instance is upgraded to a non-vulnerable version.
Event History
Frequently Asked Questions
What is the severity of CVE-2025-65518?
CVE-2025-65518 is classified as a Denial of Service vulnerability that can disrupt the web interface of Plesk Obsidian.
How do I fix CVE-2025-65518?
To fix CVE-2025-65518, upgrade Plesk Obsidian to version 18.0.74 or later.
What versions of Plesk Obsidian are affected by CVE-2025-65518?
Plesk Obsidian versions 8.0.1 through 18.0.73 are vulnerable to CVE-2025-65518.
What is the impact of CVE-2025-65518?
The impact of CVE-2025-65518 is that it can cause a Denial of Service condition, making the affected web interface unresponsive.
Where does CVE-2025-65518 occur in Plesk?
CVE-2025-65518 occurs in the get_password.php endpoint of Plesk Obsidian.