Vestacp

Vesta Control Panel

16 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.27%
  • Veröffentlicht 27.01.2026 15:23:50
  • Zuletzt bearbeitet 29.01.2026 16:31:35

VestaCP 0.9.8-26 contains a session token vulnerability in the LoginAs module that allows remote attackers to manipulate authentication tokens. Attackers can exploit insufficient token validation to access user accounts and perform unauthorized login...

Exploit
  • EPSS 0.04%
  • Veröffentlicht 21.01.2026 17:27:48
  • Zuletzt bearbeitet 26.01.2026 15:04:59

VestaCP versions prior to 0.9.8-25 contain a cross-site scripting vulnerability in the IP interface configuration that allows attackers to inject malicious scripts. Attackers can exploit the 'v_interface' parameter by sending a crafted POST request t...

Exploit
  • EPSS 15.92%
  • Veröffentlicht 24.10.2022 14:15:50
  • Zuletzt bearbeitet 07.05.2025 15:15:52

myVesta Control Panel before 0.9.8-26-43 and Vesta Control Panel before 0.9.8-26 are vulnerable to command injection. An authenticated and remote administrative user can execute arbitrary commands via the v_sftp_license parameter when sending HTTP PO...

Exploit
  • EPSS 0.23%
  • Veröffentlicht 19.07.2022 19:15:11
  • Zuletzt bearbeitet 21.11.2024 07:12:44

Vesta v1.0.0-5 was discovered to contain a cross-site scripting (XSS) vulnerability via the generate_response function at /web/api/v1/upload/UploadHandler.php.

Exploit
  • EPSS 0.23%
  • Veröffentlicht 19.07.2022 19:15:11
  • Zuletzt bearbeitet 21.11.2024 07:12:44

Vesta v1.0.0-5 was discovered to contain a cross-site scripting (XSS) vulnerability via the body function at /web/api/v1/upload/UploadHandler.php.

Exploit
  • EPSS 0.23%
  • Veröffentlicht 19.07.2022 19:15:10
  • Zuletzt bearbeitet 21.11.2024 07:08:47

Vesta v1.0.0-5 was discovered to contain a cross-site scripting (XSS) vulnerability via the post function at /web/api/v1/upload/UploadHandler.php.

Exploit
  • EPSS 0.23%
  • Veröffentlicht 19.07.2022 19:15:10
  • Zuletzt bearbeitet 21.11.2024 07:12:44

Vesta v1.0.0-5 was discovered to contain a cross-site scripting (XSS) vulnerability via the handle_file_upload function at /web/api/v1/upload/UploadHandler.php.

Exploit
  • EPSS 0.36%
  • Veröffentlicht 29.11.2021 15:15:08
  • Zuletzt bearbeitet 21.11.2024 06:29:37

vesta 0.9.8-24 is affected by a file inclusion vulnerability in file web/add/user/index.php.

Exploit
  • EPSS 0.8%
  • Veröffentlicht 08.04.2021 14:15:14
  • Zuletzt bearbeitet 21.11.2024 06:03:58

VestaCP through 0.9.8-24 allows the admin user to escalate privileges to root because the Sudo configuration does not require a password to run /usr/local/vesta/bin scripts.

Exploit
  • EPSS 3.29%
  • Veröffentlicht 15.03.2021 06:15:12
  • Zuletzt bearbeitet 21.11.2024 05:59:37

web/upload/UploadHandler.php in Vesta Control Panel (aka VestaCP) through 0.9.8-27 and myVesta through 0.9.8-26-39 allows uploads from a different origin.