PT-2022-12942 · Unknown · Vesta Control Panel

CVE-2021-46850

·

Published

2021-03-15

·

Updated

2023-08-08

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions myVesta Control Panel versions prior to 0.9.8-26-43 Vesta Control Panel versions prior to 0.9.8-26
Description The issue allows an authenticated and remote administrative user to execute arbitrary commands. This can be achieved by sending HTTP POST requests to the "/edit/server" endpoint and exploiting the v sftp license parameter.
Recommendations For myVesta Control Panel versions prior to 0.9.8-26-43, update to version 0.9.8-26-43 or later. For Vesta Control Panel versions prior to 0.9.8-26, update to version 0.9.8-26 or later.

Exploit

Fix

Argument Injection

Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-13681
CVE-2021-46850

Affected Products

Vesta Control Panel