Skip to main content

Vendor/product archive

vestacp / control_panel CVEs

Beta · best-effort

10 CVEs tagged to vestacp / control_panel0 Critical, 5 High, 5 Medium, 0 Low, 0 Unrated.

CVE-2022-3967

Published Nov 13, 2022

A vulnerability, which was classified as critical, was found in Vesta Control Panel. Affected is an unknown function of the file func/main.sh of the component sed Handler. The man…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-30463

Published Apr 8, 2021

VestaCP through 0.9.8-24 allows attackers to gain privileges by creating symlinks to files for which they lack permissions. After reading the RKEY value from user.conf under the /…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2020-10966

Published Mar 25, 2020

In the Password Reset Module in VESTA Control Panel through 0.9.8-25 and Hestia Control Panel before 1.1.1, Host header manipulation leads to account takeover because the victim r…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-12792

Published Aug 15, 2019

A command injection vulnerability in UploadHandler.php in Vesta Control Panel 0.9.8-24 allows remote attackers to escalate from regular registered users to root.

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2019-12791

Published Aug 15, 2019

A directory traversal vulnerability in the v-list-user script in Vesta Control Panel 0.9.8-24 allows remote attackers to escalate from regular registered users to root via the pas…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2018-18547

Published Oct 24, 2018

Vesta Control Panel through 0.9.8-22 has XSS via the edit/web/ domain parameter, the list/backup/ backup parameter, the list/rrd/ period parameter, the list/directory/ dir_a param…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-10686

Published May 6, 2018

An issue was discovered in Vesta Control Panel 0.9.8-20. There is Reflected XSS via $_REQUEST['path'] to the view/file/index.php URI, which can lead to remote PHP code execution v…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2015-4117

Published Feb 28, 2018

Vesta Control Panel before 0.9.8-14 allows remote authenticated users to execute arbitrary commands via shell metacharacters in the backup parameter to list/backup/index.php.

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort
Showing 1-10 of 10 CVEsPage 1 of 1