Skip to main content

Parallels Plesk Panel Multiple Vulnerabilities

Last Update Date: 20 Jun 2014 09:23 Release Date: 20 Jun 2014 3631 Views

RISK: High Risk

TYPE: Servers - Web Servers

TYPE: Web Servers

Two vulnerabilities were identified in Parallels Plesk Panel, which can be exploited by malicious people to conduct cross-site scripting attacks and disclose potentially sensitive information.

  1. An error when parsing XML entities can be exploited to e.g. disclose data from local resources with the privileges of the sso user via a specially crafted XML document including external entity references.
  2. Certain input passed to /relay is not properly sanitised before being returned to the user. This can be exploited to execute arbitrary HTML and script code in a user's browser session in context of an affected site.

Successful exploitation of the vulnerabilities requires the Single Sign-On (SSO) service to be installed.

 

 

Note: No official solution is currently available.


Impact

  • Cross-Site Scripting
  • Information Disclosure

System / Technologies affected

  • Versions 10.4.x, 11.0.x

Solutions

  • No official solution is currently available. The vendor is planning to release an update in early July 2014.

Vulnerability Identifier

  • No CVE information is available

Source


Related Link