Unknown · Hestia Control Panel · CVE-2021-27231
Name of the Vulnerable Software and Affected Versions:
Hestia Control Panel versions 1.3.5 and below
Hestia Control Panel versions 1.3.3 and below can be consolidated into the previous line, so the final output is:
Hestia Control Panel versions 1.3.5 and below
Description:
The issue allows remote authenticated users to create a subdomain for a different customer's domain name in a shared-hosting environment, leading to potential spoofing of services or email messages.
Recommendations:
For Hestia Control Panel versions 1.3.5 and below, consider restricting subdomain creation privileges to prevent unauthorized access to other customers' domain names until a fix is available.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.