CVE-2021-46850
- EPSS 15.92%
- Veröffentlicht 24.10.2022 14:15:50
- Zuletzt bearbeitet 07.05.2025 15:15:52
myVesta Control Panel before 0.9.8-26-43 and Vesta Control Panel before 0.9.8-26 are vulnerable to command injection. An authenticated and remote administrative user can execute arbitrary commands via the v_sftp_license parameter when sending HTTP PO...
CVE-2022-36304
- EPSS 0.22%
- Veröffentlicht 19.07.2022 19:15:11
- Zuletzt bearbeitet 21.11.2024 07:12:44
Vesta v1.0.0-5 was discovered to contain a cross-site scripting (XSS) vulnerability via the generate_response function at /web/api/v1/upload/UploadHandler.php.
CVE-2022-36305
- EPSS 0.22%
- Veröffentlicht 19.07.2022 19:15:11
- Zuletzt bearbeitet 21.11.2024 07:12:44
Vesta v1.0.0-5 was discovered to contain a cross-site scripting (XSS) vulnerability via the body function at /web/api/v1/upload/UploadHandler.php.
CVE-2022-34025
- EPSS 0.22%
- Veröffentlicht 19.07.2022 19:15:10
- Zuletzt bearbeitet 21.11.2024 07:08:47
Vesta v1.0.0-5 was discovered to contain a cross-site scripting (XSS) vulnerability via the post function at /web/api/v1/upload/UploadHandler.php.
CVE-2022-36303
- EPSS 0.22%
- Veröffentlicht 19.07.2022 19:15:10
- Zuletzt bearbeitet 21.11.2024 07:12:44
Vesta v1.0.0-5 was discovered to contain a cross-site scripting (XSS) vulnerability via the handle_file_upload function at /web/api/v1/upload/UploadHandler.php.
CVE-2021-43693
- EPSS 0.36%
- Veröffentlicht 29.11.2021 15:15:08
- Zuletzt bearbeitet 21.11.2024 06:29:37
vesta 0.9.8-24 is affected by a file inclusion vulnerability in file web/add/user/index.php.
- EPSS 0.8%
- Veröffentlicht 08.04.2021 14:15:14
- Zuletzt bearbeitet 21.11.2024 06:03:58
VestaCP through 0.9.8-24 allows the admin user to escalate privileges to root because the Sudo configuration does not require a password to run /usr/local/vesta/bin scripts.
CVE-2021-28379
- EPSS 3.29%
- Veröffentlicht 15.03.2021 06:15:12
- Zuletzt bearbeitet 21.11.2024 05:59:37
web/upload/UploadHandler.php in Vesta Control Panel (aka VestaCP) through 0.9.8-27 and myVesta through 0.9.8-26-39 allows uploads from a different origin.
- EPSS 2.44%
- Veröffentlicht 21.04.2020 17:15:12
- Zuletzt bearbeitet 21.11.2024 04:56:04
A remote command execution in Vesta Control Panel through 0.9.8-26 allows any authenticated user to execute arbitrary commands on the system via cron jobs.
- EPSS 0.45%
- Veröffentlicht 21.04.2020 17:15:12
- Zuletzt bearbeitet 21.11.2024 04:56:04
An elevation of privilege in Vesta Control Panel through 0.9.8-26 allows an attacker to gain root system access from the admin account via v-change-user-password (aka the user password change script).