Plesk privilege escalation | CVE-2021-45008
NAME
Plesk privilege escalation
- Platforms Affected:
Plesk Plesk 18.0.37 - Risk Level:
8.8 - Exploitability:
Unproven - Consequences:
Gain Privileges
DESCRIPTION
Plesk could allow a remote authenticated attacker to gain elevated privileges on the system, caused by insecure permissions in the Super admin flag parameter. An attacker could exploit this vulnerability to gain administrative privileges.
CVSS 3.0 Information
- Privileges Required: Low
- User Interaction: None
- Scope: Unchanged
- Access Vector: Network
- Access Complexity: Low
- Confidentiality Impact: High
- Integrity Impact: High
- Availability Impact: High
- Remediation Level: Official Fix
MITIGATION
Upgrade to the latest version of Plesk (18.0.41 Update 1 or later), available from the Plesk Web site. See References.
- Reference Link:
https://github.com/AS4mir/CVE-2021-45008/blob/main/README.md - Reference Link:
https://www.plesk.com/
If you like the site, please consider joining the telegram channel and supporting us on Patreon using the button below.