PT-2023-6601 · Plesk · Plesk Obsidian
Tjetnipat
·
Published
2023-01-21
·
Updated
2025-04-02
·
CVE-2023-24044
CVSS v2.0
6.4
Medium
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
Plesk Obsidian versions through 18.0.49
Description
A Host Header Injection issue on the Login page allows attackers to redirect users to malicious websites via a Host request header. The issue is related to the ability to use arbitrary domain names to access the panel, which the vendor considers an intended feature. This can be exploited by sending a specially crafted
Host HTTP request header, potentially allowing a remote attacker to redirect users to arbitrary websites.Recommendations
For Plesk Obsidian versions through 18.0.49, consider restricting access to the Login page or disabling the ability to use arbitrary domain names to access the panel as a temporary workaround until a fix is available. Avoid using the
Host request header in the affected API endpoint until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this issue.Exploit
Fix
Open Redirect
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Plesk Obsidian