6.5
CVSSv2

CVE-2021-45008

Published: 21/02/2022 Updated: 11/04/2024
CVSS v2 Base Score: 6.5 | Impact Score: 6.4 | Exploitability Score: 8
CVSS v3 Base Score: 8.8 | Impact Score: 5.9 | Exploitability Score: 2.8
VMScore: 578
Vector: AV:N/AC:L/Au:S/C:P/I:P/A:P

Vulnerability Summary

Plesk CMS 18.0.37 is affected by an insecure permissions vulnerability that allows privilege Escalation from user to admin rights. OTE: the vendor states that this is only a site-specific problem on websites of one or more Plesk users

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

plesk plesk 18.0.37

Github Repositories

CVE-2021-45008 Privilege Escalation from user to admin Affected product and version: Plesk Obsidian 18037 Severity: Critical Impact: Gain high privilege from user to admin and access critical information Description: insecure permissions vulnerability that allows unprivilege user to get admin rights Steps to reproduce: Login with user account with low roles Capture the requ