Plesk Password-Protected Directories Local Privilege Escalation Vulnerability
Vulnerability
A local privilege escalation vulnerability has been identified in Plesk version 18.0, specifically within the Password-Protected Directories feature. This issue allows users to inject data into the Apache configuration, enabling them to execute commands as the root user. The vulnerability arises from incorrect access control, which could be exploited by any Plesk user with access to the feature.
Impact
Exploitation of this vulnerability could lead to unauthorized root-level access on the server.
Remediation
Users can update Plesk to the latest version to address this vulnerability. Instructions for updating Plesk are available in the Plesk update guide.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
