Vestacp

Vesta Control Panel

14 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 15.92%
  • Veröffentlicht 24.10.2022 14:15:50
  • Zuletzt bearbeitet 07.05.2025 15:15:52

myVesta Control Panel before 0.9.8-26-43 and Vesta Control Panel before 0.9.8-26 are vulnerable to command injection. An authenticated and remote administrative user can execute arbitrary commands via the v_sftp_license parameter when sending HTTP PO...

Exploit
  • EPSS 0.22%
  • Veröffentlicht 19.07.2022 19:15:11
  • Zuletzt bearbeitet 21.11.2024 07:12:44

Vesta v1.0.0-5 was discovered to contain a cross-site scripting (XSS) vulnerability via the generate_response function at /web/api/v1/upload/UploadHandler.php.

Exploit
  • EPSS 0.22%
  • Veröffentlicht 19.07.2022 19:15:11
  • Zuletzt bearbeitet 21.11.2024 07:12:44

Vesta v1.0.0-5 was discovered to contain a cross-site scripting (XSS) vulnerability via the body function at /web/api/v1/upload/UploadHandler.php.

Exploit
  • EPSS 0.22%
  • Veröffentlicht 19.07.2022 19:15:10
  • Zuletzt bearbeitet 21.11.2024 07:08:47

Vesta v1.0.0-5 was discovered to contain a cross-site scripting (XSS) vulnerability via the post function at /web/api/v1/upload/UploadHandler.php.

Exploit
  • EPSS 0.22%
  • Veröffentlicht 19.07.2022 19:15:10
  • Zuletzt bearbeitet 21.11.2024 07:12:44

Vesta v1.0.0-5 was discovered to contain a cross-site scripting (XSS) vulnerability via the handle_file_upload function at /web/api/v1/upload/UploadHandler.php.

Exploit
  • EPSS 0.36%
  • Veröffentlicht 29.11.2021 15:15:08
  • Zuletzt bearbeitet 21.11.2024 06:29:37

vesta 0.9.8-24 is affected by a file inclusion vulnerability in file web/add/user/index.php.

Exploit
  • EPSS 0.8%
  • Veröffentlicht 08.04.2021 14:15:14
  • Zuletzt bearbeitet 21.11.2024 06:03:58

VestaCP through 0.9.8-24 allows the admin user to escalate privileges to root because the Sudo configuration does not require a password to run /usr/local/vesta/bin scripts.

Exploit
  • EPSS 3.29%
  • Veröffentlicht 15.03.2021 06:15:12
  • Zuletzt bearbeitet 21.11.2024 05:59:37

web/upload/UploadHandler.php in Vesta Control Panel (aka VestaCP) through 0.9.8-27 and myVesta through 0.9.8-26-39 allows uploads from a different origin.

  • EPSS 2.44%
  • Veröffentlicht 21.04.2020 17:15:12
  • Zuletzt bearbeitet 21.11.2024 04:56:04

A remote command execution in Vesta Control Panel through 0.9.8-26 allows any authenticated user to execute arbitrary commands on the system via cron jobs.

  • EPSS 0.45%
  • Veröffentlicht 21.04.2020 17:15:12
  • Zuletzt bearbeitet 21.11.2024 04:56:04

An elevation of privilege in Vesta Control Panel through 0.9.8-26 allows an attacker to gain root system access from the admin account via v-change-user-password (aka the user password change script).