6.8
CVSSv2

CVE-2021-28379

Published: 15/03/2021 Updated: 19/03/2021
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
CVSS v3 Base Score: 8.8 | Impact Score: 5.9 | Exploitability Score: 2.8
VMScore: 605
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

web/upload/UploadHandler.php in Vesta Control Panel (aka VestaCP) up to and including 0.9.8-27 and myVesta up to and including 0.9.8-26-39 allows uploads from a different origin.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

myvestacp myvesta

vestacp vesta control panel

Exploits

VestaCP version 098 suffers from a cross site request forgery that can be leveraged to add remote ssh access ...