4.3
CVSSv2

CVE-2021-45007

Published: 20/02/2022 Updated: 11/04/2024
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 6.5 | Impact Score: 3.6 | Exploitability Score: 2.8
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

Plesk 18.0.37 is affected by a Cross Site Request Forgery (CSRF) vulnerability that allows an malicious user to insert data on the user and admin panel. NOTE: the vendor states that this is only a site-specific problem on websites of one or more Plesk users

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

plesk plesk 18.0.37

Github Repositories

Cross-Site Request Forgery

CVE-2021-45007 #Cross-Site Request Forgery Affected product and version: Plesk Obsidian 18037 Severity: High Impact: Submit requests with attacker information Description: CSRF could let the attacker to submit new requests because there isn’t any CSRF_token protection sent with requests to server Steps to reproduce: Login and try to submit any request Capture the requ