myVesta Control Panel before 0.9.8-26-43 and Vesta Control Panel before 0.9.8-26 are vulnerable to command injection. An authenticated and remote administrative user can execute arbitrary commands via the v_sftp_license parameter when sending HTTP POST requests to the /edit/server endpoint.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: mitre
Published: 2022-10-24T00:00:00
Updated: 2024-08-04T05:17:42.463Z
Reserved: 2022-10-24T00:00:00
Link: CVE-2021-46850
Vulnrichment
No data.
NVD
Status : Modified
Published: 2022-10-24T14:15:50.067
Modified: 2024-11-21T06:34:48.320
Link: CVE-2021-46850
Redhat
No data.