The feature to preview a website in... CVE-2021-35976

4.3 AV AC AU C I A
发布: 2021-09-10
修订: 2024-11-21

The feature to preview a website in Plesk Obsidian 18.0.0 through 18.0.32 on Linux is vulnerable to reflected XSS via the /plesk-site-preview/ PATH, aka PFSI-62467. The attacker could execute JavaScript code in the victim's browser by using the link to preview sites hosted on the server. Authentication is not required to exploit the vulnerability.

0%
暂无可用Exp或PoC
当前有1条受影响产品信息