PT-2026-4927 · Vestacp · Vestacp

Vulnerability-Lab

·

Publicado

2026-01-27

·

Atualizado

2026-01-27

·

CVE-2020-36948

CVSS v3.1

9.8

Crítica

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions VestaCP version 0.9.8-26
Description The software contains a session token issue within the LoginAs module. This allows remote attackers to manipulate authentication tokens due to insufficient validation. Exploitation can lead to unauthorized access to user accounts and login requests without administrative privileges.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Incorrect Authorization

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2020-36948

Produtos afetados

Vestacp