Parallels Plesk Panel Multiple Vulnerabilities
Last Update Date:
20 Jun 2014 09:23
Release Date:
20 Jun 2014
3631
Views
RISK: High Risk
TYPE: Servers - Web Servers
Two vulnerabilities were identified in Parallels Plesk Panel, which can be exploited by malicious people to conduct cross-site scripting attacks and disclose potentially sensitive information.
- An error when parsing XML entities can be exploited to e.g. disclose data from local resources with the privileges of the sso user via a specially crafted XML document including external entity references.
- Certain input passed to /relay is not properly sanitised before being returned to the user. This can be exploited to execute arbitrary HTML and script code in a user's browser session in context of an affected site.
Successful exploitation of the vulnerabilities requires the Single Sign-On (SSO) service to be installed.
Note: No official solution is currently available.
Impact
- Cross-Site Scripting
- Information Disclosure
System / Technologies affected
- Versions 10.4.x, 11.0.x
Solutions
- No official solution is currently available. The vendor is planning to release an update in early July 2014.
Vulnerability Identifier
- No CVE information is available
Source
Related Link
Share with