Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2021-30463

Опубликовано: 08 апр. 2021
Источник: nvd
CVSS3: 7.8
CVSS2: 7.2
EPSS Низкий

Описание

VestaCP through 0.9.8-24 allows attackers to gain privileges by creating symlinks to files for which they lack permissions. After reading the RKEY value from user.conf under the /usr/local/vesta/data/users/admin directory, the admin password can be changed via a /reset/?action=confirm&user=admin&code= URI. This occurs because chmod is used unsafely.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:vestacp:control_panel:*:*:*:*:*:*:*:*
Версия до 0.9.8-24 (включая)

EPSS

Процентиль: 18%
0.00056
Низкий

7.8 High

CVSS3

7.2 High

CVSS2

Дефекты

CWE-59

Связанные уязвимости

github
больше 3 лет назад

VestaCP through 0.9.8-24 allows attackers to gain privileges by creating symlinks to files for which they lack permissions. After reading the RKEY value from user.conf under the /usr/local/vesta/data/users/admin directory, the admin password can be changed via a /reset/?action=confirm&user=admin&code= URI. This occurs because chmod is used unsafely.

EPSS

Процентиль: 18%
0.00056
Низкий

7.8 High

CVSS3

7.2 High

CVSS2

Дефекты

CWE-59