VestaCP through 0.9.8-24 allows the admin user to escalate privileges to root because the Sudo configuration does not require a password to run /usr/local/vesta/bin scripts.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:HVestacp Vesta Control Panel
APPVestacp≤ 0.9.8-24
🟢
PATCH AVAILABLE
Vendor update available. Deploy in standard maintenance cycle.
Tags
LPE
CWE
Related vulnerabilities
CVE-2021-43693CRITICAL9.8PL ✓same product
File inclusion w Vesta Control Panel 0.9.8-24 — krytyczna podatność RCE
CVE-2018-1000884CRITICAL9.8PL ✓same product
Vesta CP: ujawnienie kodu reset hasła przez timing attack
CVE-2021-46850HIGH7.2same product
myVesta Control Panel before 0.9.8-26-43 and Vesta Control Panel before 0.9.8-26 are vulnerable to command inj...
CVE-2021-28379HIGH8.8same product
web/upload/UploadHandler.php in Vesta Control Panel (aka VestaCP) through 0.9.8-27 and myVesta through 0.9.8-2...
CVE-2020-10787HIGH8.8same product
An elevation of privilege in Vesta Control Panel through 0.9.8-26 allows an attacker to gain root system acces...