A remote command execution in Vesta Control Panel through 0.9.8-26 allows any authenticated user to execute arbitrary commands on the system via cron jobs.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HVestacp Vesta Control Panel
APPVestacp≤ 0.9.8-26
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
Related vulnerabilities
CVE-2021-43693CRITICAL9.8PL ✓same product
File inclusion w Vesta Control Panel 0.9.8-24 — krytyczna podatność RCE
CVE-2018-1000884CRITICAL9.8PL ✓same product
Vesta CP: ujawnienie kodu reset hasła przez timing attack
CVE-2021-46850HIGH7.2same product
myVesta Control Panel before 0.9.8-26-43 and Vesta Control Panel before 0.9.8-26 are vulnerable to command inj...
CVE-2021-30462HIGH7.2same product
VestaCP through 0.9.8-24 allows the admin user to escalate privileges to root because the Sudo configuration d...
CVE-2021-28379HIGH8.8same product
web/upload/UploadHandler.php in Vesta Control Panel (aka VestaCP) through 0.9.8-27 and myVesta through 0.9.8-2...