web/upload/UploadHandler.php in Vesta Control Panel (aka VestaCP) through 0.9.8-27 and myVesta through 0.9.8-26-39 allows uploads from a different origin.
oryginał ENCVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HMyvestacp Myvesta
APPMyvestacp≤ 0.9.8-26-39Vestacp Vesta Control Panel
APPVestacp≤ 0.9.8-27
🔵
ZWERYFIKUJ U PRODUCENTA
Brak jednoznacznych danych o patchu. Sprawdź referencje od producenta.
CWE
Powiązane podatności
CVE-2021-43693CRITICAL9.8PL ✓ten sam produkt
File inclusion w Vesta Control Panel 0.9.8-24 — krytyczna podatność RCE
CVE-2018-1000884CRITICAL9.8PL ✓ten sam produkt
Vesta CP: ujawnienie kodu reset hasła przez timing attack
CVE-2021-46850HIGH7.2ten sam produkt
myVesta Control Panel before 0.9.8-26-43 and Vesta Control Panel before 0.9.8-26 are vulnerable to command inj...
CVE-2021-30462HIGH7.2ten sam produkt
VestaCP through 0.9.8-24 allows the admin user to escalate privileges to root because the Sudo configuration d...
CVE-2020-10787HIGH8.8ten sam produkt
An elevation of privilege in Vesta Control Panel through 0.9.8-26 allows an attacker to gain root system acces...