Vulnerability Details CVE-2023-0829
Plesk 17.0 through 18.0.31 version, is vulnerable to a Cross-Site Scripting. A malicious subscription owner (either a customer or an additional user), can fully compromise the server if an administrator visits a certain page in Plesk related to the malicious subscription.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.001
EPSS Ranking 26.3%
CVSS Severity
CVSS v3 Score 8.8
Products affected by CVE-2023-0829
-
cpe:2.3:a:plesk:plesk:18.0.28
-
cpe:2.3:a:plesk:plesk:18.0.29
-
cpe:2.3:a:plesk:plesk:18.0.30
-
cpe:2.3:a:plesk:plesk:18.0.31