PT-2020-12321 · Vesta · Vesta Control Panel

Published

2020-04-21

·

Updated

2021-07-21

·

CVE-2020-10787

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Vesta Control Panel versions 0.9.8-26
Description The issue allows an attacker to gain root system access from the admin account via the v-change-user-password script, also known as the user password change script. This script is used to change user passwords, and its vulnerability can be exploited to elevate privileges.
Recommendations For Vesta Control Panel versions 0.9.8-26, consider disabling the v-change-user-password script until a patch is available to prevent potential exploitation and elevation of privilege.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2020-10787

Affected Products

Vesta Control Panel