PT-2026-57247 · Hestiacp · Hestiacp
CVSS v3.1
5.4
Medium
| Vector | AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
HestiaCP versions prior to 1.9.5
Description
An authenticated low-privilege user can perform a stored cross-site scripting attack by creating a DNS record containing a double-quote followed by a script payload in the value field. The issue occurs because the application does not use the
htmlspecialchars() function to encode the DNS record value when it is rendered within the data-sort-value HTML attribute in the 'list dns rec.php' endpoint. This allows the injected script to execute in the browser of any user who views the DNS record list, including those with administrator privileges.Recommendations
Update HestiaCP to version 1.9.5 or later.
Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Hestiacp