Plesk Obsidian

CPE Details

Plesk Obsidian
-
2022-11-10
14h52 +00:00
2023-02-21
16h43 +00:00
Alerte pour un CPE
Restez informé de toutes modifications pour un CPE spécifique.
Gestion des notifications

CPE Name: cpe:2.3:a:plesk:obsidian:-:*:*:*:*:*:*:*

Informations

Vendor

plesk

Product

obsidian

Version

-

Related CVE

Open and find in CVE List

CVE ID Publié Description Score Gravité
CVE-2023-24044 2023-01-21 23h00 +00:00 A Host Header Injection issue on the Login page of Plesk Obsidian through 18.0.49 allows attackers to redirect users to malicious websites via a Host request header. NOTE: the vendor's position is "the ability to use arbitrary domain names to access the panel is an intended feature."
6.1
Moyen
CVE-2022-45130 2022-11-09 23h00 +00:00 Plesk Obsidian allows a CSRF attack, e.g., via the /api/v2/cli/commands REST API to change an Admin password. NOTE: Obsidian is a specific version of the Plesk product: version numbers were used through version 12, and then the convention was changed so that versions are identified by names ("Obsidian"), not numbers.
6.5
Moyen