Plesk

Obsidian

7 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.04%
  • Veröffentlicht 08.01.2026 00:00:00
  • Zuletzt bearbeitet 30.01.2026 01:08:45

Plesk Obsidian versions 8.0.1 through 18.0.73 are vulnerable to a Denial of Service (DoS) condition. The vulnerability exists in the get_password.php endpoint, where a crafted request containing a malicious payload can cause the affected web interfac...

  • EPSS 0.06%
  • Veröffentlicht 19.08.2025 00:00:00
  • Zuletzt bearbeitet 26.08.2025 15:15:47

In Plesk Obsidian 18.0.70, _isAdminPasswordValid uses an == comparison. Thus, if the correct password is "0e" followed by any digit string, then an attacker can login with any other string that evaluates to 0.0 (such as the 0e0 string). This occurs i...

  • EPSS 0.04%
  • Veröffentlicht 03.07.2025 00:00:00
  • Zuletzt bearbeitet 03.07.2025 15:13:53

In Plesk Obsidian 18.0.69, unauthenticated requests to /login_up.php can reveal an AWS accessKeyId, secretAccessKey, region, and endpoint.

Exploit
  • EPSS 57.42%
  • Veröffentlicht 22.01.2023 03:15:09
  • Zuletzt bearbeitet 02.04.2025 16:15:33

A Host Header Injection issue on the Login page of Plesk Obsidian through 18.0.49 allows attackers to redirect users to malicious websites via a Host request header. NOTE: the vendor's position is "the ability to use arbitrary domain names to access ...

Exploit
  • EPSS 0.76%
  • Veröffentlicht 10.11.2022 06:15:13
  • Zuletzt bearbeitet 01.05.2025 14:15:34

Plesk Obsidian allows a CSRF attack, e.g., via the /api/v2/cli/commands REST API to change an Admin password. NOTE: Obsidian is a specific version of the Plesk product: version numbers were used through version 12, and then the convention was changed...

Exploit
  • EPSS 0.53%
  • Veröffentlicht 10.09.2021 12:15:13
  • Zuletzt bearbeitet 21.11.2024 06:12:52

The feature to preview a website in Plesk Obsidian 18.0.0 through 18.0.32 on Linux is vulnerable to reflected XSS via the /plesk-site-preview/ PATH, aka PFSI-62467. The attacker could execute JavaScript code in the victim's browser by using the link ...

  • EPSS 1.87%
  • Veröffentlicht 03.08.2020 21:15:10
  • Zuletzt bearbeitet 21.11.2024 04:58:10

A GET-based XSS reflected vulnerability in Plesk Obsidian 18.0.17 allows remote unauthenticated users to inject arbitrary JavaScript, HTML, or CSS via a GET parameter.