Lucene search

K
cnvdChina National Vulnerability DatabaseCNVD-2022-91163
HistoryFeb 22, 2022 - 12:00 a.m.

Plesk Cross-Site Request Forgery Vulnerability (CNVD-2022-91163)

2022-02-2200:00:00
China National Vulnerability Database
www.cnvd.org.cn
17
plesk
hosting control panel
cross-site request forgery
version 18.0.37
swiss company
validation
administration panel
data insertion

EPSS

0.001

Percentile

28.2%

Plesk is a hosting control panel from the Swiss company Plesk. version 18.0.37 of Plesk is vulnerable to cross-site request forgery, which stems from the software’s lack of validation of cross-site request forgery tokens. An attacker could exploit this vulnerability to insert data in the user and administration panels.

EPSS

0.001

Percentile

28.2%