PT-2022-12942 · Unknown · Vesta Control Panel

Published

2022-10-24

·

Updated

2023-08-08

·

CVE-2021-46850

CVSS v3.1

7.2

High

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions myVesta Control Panel versions prior to 0.9.8-26-43 Vesta Control Panel versions prior to 0.9.8-26
Description The issue allows an authenticated and remote administrative user to execute arbitrary commands. This can be achieved by sending HTTP POST requests to the "/edit/server" endpoint and exploiting the v sftp license parameter.
Recommendations For myVesta Control Panel versions prior to 0.9.8-26-43, update to version 0.9.8-26-43 or later. For Vesta Control Panel versions prior to 0.9.8-26, update to version 0.9.8-26 or later.

Exploit

Fix

Argument Injection

Weakness Enumeration

Related Identifiers

CVE-2021-46850

Affected Products

Vesta Control Panel