PT-2020-12321 · Vesta · Vesta Control Panel
Published
2020-04-21
·
Updated
2021-07-21
·
CVE-2020-10787
CVSS v2.0
9.0
High
| Vector | AV:N/AC:L/Au:S/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Vesta Control Panel versions 0.9.8-26
Description
The issue allows an attacker to gain root system access from the admin account via the
v-change-user-password script, also known as the user password change script. This script is used to change user passwords, and its vulnerability can be exploited to elevate privileges.Recommendations
For Vesta Control Panel versions 0.9.8-26, consider disabling the
v-change-user-password script until a patch is available to prevent potential exploitation and elevation of privilege.Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Vesta Control Panel