An issue in DirectAdmin v1.680 allows unauthorized attackers to manipulate the page layout and replace the legitimate login interface with arbitrary attacker-controlled content via supplying a crafted GET request.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:NDirectadmin
APPDirectadmin1.680
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
Related vulnerabilities
CVE-2017-18045CRITICAL9.8PL ✓same product
JBMC DirectAdmin – nieautoryzowany dostęp lub DoS przy zmianie hasła
CVE-2019-9625HIGH8.8same product
JBMC DirectAdmin 1.55 allows CSRF via the /CMD_ACCOUNT_ADMIN URI to create a new admin account.
CVE-2009-1525HIGH8.5same product
CMD_DB in JBMC Software DirectAdmin before 1.334 allows remote authenticated users to gain privileges via shel...
CVE-2019-11193MEDIUM6.1same product
The FileManager in InfinitumIT DirectAdmin through v1.561 has XSS via CMD_FILE_MANAGER, CMD_SHOW_USER, and CMD...
CVE-2012-5305MEDIUM4.3same product
Cross-site scripting (XSS) vulnerability in CMD_DOMAIN in JBMC Software DirectAdmin 1.403 allows remote attack...