CVE-2023-24044
CVSS V2 None
CVSS V3 None
Description
** DISPUTED ** A Host Header Injection issue on the Login page of Plesk Obsidian through 18.0.49 allows attackers to redirect users to malicious websites via a Host request header. NOTE: the vendor's position is "the ability to use arbitrary domain names to access the panel is an intended feature."
Overview
- CVE ID
- CVE-2023-24044
- Assigner
- cve@mitre.org
- Vulnerability Status
- Modified
- Published Version
- 2023-01-22T03:15:09
- Last Modified Date
- 2023-02-28T16:15:09
Weakness Enumerations
CPE Configuration (Product)
CPE | Vulnerable | Operator | Version Start | Version End |
---|---|---|---|---|
cpe:2.3:a:plesk:obsidian:*:*:*:*:*:*:*:* | 1 | OR | 18.0.49 |
References
Reference URL | Reference Tags |
---|---|
https://gist.github.com/TJetnipat/02b3854543b7ec95d54a8de811f2e8ae | Exploit Third Party Advisory |
https://medium.com/@jetnipat.tho/cve-2023-24044-10e48ab940d8 | Exploit Third Party Advisory |
https://support.plesk.com/hc/en-us/articles/10254625170322-Vulnerability-CVE-2023-24044 |
Sources
Source Name | Source URL |
---|---|
NIST | https://nvd.nist.gov/vuln/detail/CVE-2023-24044 |
MITRE | https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-24044 |
History
Created | Old Value | New Value | Data Type | Notes |
---|---|---|---|---|
2023-01-22 04:16:08 | Added to TrackCVE | |||
2023-01-23 15:14:32 | 2023-01-23T15:08:08 | CVE Modified Date | updated | |
2023-01-23 15:14:32 | Received | Awaiting Analysis | Vulnerability Status | updated |
2023-01-27 20:15:19 | Awaiting Analysis | Undergoing Analysis | Vulnerability Status | updated |
2023-01-30 21:13:48 | 2023-01-30T17:41:10 | CVE Modified Date | updated | |
2023-01-30 21:13:48 | Undergoing Analysis | Analyzed | Vulnerability Status | updated |
2023-01-30 21:13:49 | Weakness Enumeration | new | ||
2023-01-30 21:13:51 | CPE Information | updated | ||
2023-02-28 17:15:13 | 2023-02-28T16:15:09 | CVE Modified Date | updated | |
2023-02-28 17:15:13 | Analyzed | Modified | Vulnerability Status | updated |
2023-02-28 17:15:14 | A Host Header Injection issue on the Login page of Plesk Obsidian through 18.0.49 allows attackers to redirect users to malicious websites via a Host request header. | ** DISPUTED ** A Host Header Injection issue on the Login page of Plesk Obsidian through 18.0.49 allows attackers to redirect users to malicious websites via a Host request header. NOTE: the vendor's position is "the ability to use arbitrary domain names to access the panel is an intended feature." | Description | updated |
2023-02-28 17:15:14 | References | updated |