Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-pxpj-pwq4-m64x

Опубликовано: 27 янв. 2026
Источник: github
Github: Не прошло ревью
CVSS4: 8.7
CVSS3: 9.8

Описание

VestaCP 0.9.8-26 contains a session token vulnerability in the LoginAs module that allows remote attackers to manipulate authentication tokens. Attackers can exploit insufficient token validation to access user accounts and perform unauthorized login requests without proper administrative permissions.

VestaCP 0.9.8-26 contains a session token vulnerability in the LoginAs module that allows remote attackers to manipulate authentication tokens. Attackers can exploit insufficient token validation to access user accounts and perform unauthorized login requests without proper administrative permissions.

EPSS

Процентиль: 47%
0.00238
Низкий

8.7 High

CVSS4

9.8 Critical

CVSS3

Дефекты

CWE-863

Связанные уязвимости

CVSS3: 9.8
nvd
12 дней назад

VestaCP 0.9.8-26 contains a session token vulnerability in the LoginAs module that allows remote attackers to manipulate authentication tokens. Attackers can exploit insufficient token validation to access user accounts and perform unauthorized login requests without proper administrative permissions.

EPSS

Процентиль: 47%
0.00238
Низкий

8.7 High

CVSS4

9.8 Critical

CVSS3

Дефекты

CWE-863