CVE-2020-36948
- EPSS 0.27%
- Veröffentlicht 27.01.2026 15:23:50
- Zuletzt bearbeitet 29.01.2026 16:31:35
VestaCP 0.9.8-26 contains a session token vulnerability in the LoginAs module that allows remote attackers to manipulate authentication tokens. Attackers can exploit insufficient token validation to access user accounts and perform unauthorized login...
CVE-2021-47873
- EPSS 0.04%
- Veröffentlicht 21.01.2026 17:27:48
- Zuletzt bearbeitet 26.01.2026 15:04:59
VestaCP versions prior to 0.9.8-25 contain a cross-site scripting vulnerability in the IP interface configuration that allows attackers to inject malicious scripts. Attackers can exploit the 'v_interface' parameter by sending a crafted POST request t...
CVE-2021-46850
- EPSS 15.92%
- Veröffentlicht 24.10.2022 14:15:50
- Zuletzt bearbeitet 07.05.2025 15:15:52
myVesta Control Panel before 0.9.8-26-43 and Vesta Control Panel before 0.9.8-26 are vulnerable to command injection. An authenticated and remote administrative user can execute arbitrary commands via the v_sftp_license parameter when sending HTTP PO...
CVE-2022-36304
- EPSS 0.23%
- Veröffentlicht 19.07.2022 19:15:11
- Zuletzt bearbeitet 21.11.2024 07:12:44
Vesta v1.0.0-5 was discovered to contain a cross-site scripting (XSS) vulnerability via the generate_response function at /web/api/v1/upload/UploadHandler.php.
CVE-2022-36305
- EPSS 0.23%
- Veröffentlicht 19.07.2022 19:15:11
- Zuletzt bearbeitet 21.11.2024 07:12:44
Vesta v1.0.0-5 was discovered to contain a cross-site scripting (XSS) vulnerability via the body function at /web/api/v1/upload/UploadHandler.php.
CVE-2022-34025
- EPSS 0.23%
- Veröffentlicht 19.07.2022 19:15:10
- Zuletzt bearbeitet 21.11.2024 07:08:47
Vesta v1.0.0-5 was discovered to contain a cross-site scripting (XSS) vulnerability via the post function at /web/api/v1/upload/UploadHandler.php.
CVE-2022-36303
- EPSS 0.23%
- Veröffentlicht 19.07.2022 19:15:10
- Zuletzt bearbeitet 21.11.2024 07:12:44
Vesta v1.0.0-5 was discovered to contain a cross-site scripting (XSS) vulnerability via the handle_file_upload function at /web/api/v1/upload/UploadHandler.php.
CVE-2021-43693
- EPSS 0.36%
- Veröffentlicht 29.11.2021 15:15:08
- Zuletzt bearbeitet 21.11.2024 06:29:37
vesta 0.9.8-24 is affected by a file inclusion vulnerability in file web/add/user/index.php.
- EPSS 0.8%
- Veröffentlicht 08.04.2021 14:15:14
- Zuletzt bearbeitet 21.11.2024 06:03:58
VestaCP through 0.9.8-24 allows the admin user to escalate privileges to root because the Sudo configuration does not require a password to run /usr/local/vesta/bin scripts.
CVE-2021-28379
- EPSS 3.29%
- Veröffentlicht 15.03.2021 06:15:12
- Zuletzt bearbeitet 21.11.2024 05:59:37
web/upload/UploadHandler.php in Vesta Control Panel (aka VestaCP) through 0.9.8-27 and myVesta through 0.9.8-26-39 allows uploads from a different origin.