CVE-2021-35976

The feature to preview a website in Plesk Obsidian 18.0.0 through 18.0.32 on Linux is vulnerable to reflected XSS via the /plesk-site-preview/ PATH, aka PFSI-62467. The attacker could execute JavaScript code in the victim's browser by using the link to preview sites hosted on the server. Authentication is not required to exploit the vulnerability.
Configurations

Configuration 1 (hide)

cpe:2.3:a:plesk:obsidian:*:*:*:*:*:*:*:*

History

28 Nov 2021, 23:18

Type Values Removed Values Added
References (MISC) https://www.bouali.io/cves/cve-2021-35976 - (MISC) https://www.bouali.io/cves/cve-2021-35976 - Broken Link

17 Nov 2021, 22:18

Type Values Removed Values Added
References
  • (MISC) https://www.bouali.io/cves/cve-2021-35976 -

10 Nov 2021, 01:17

Type Values Removed Values Added
References
  • {'url': 'https://www.bouali.io/cves/cve-2021-35976', 'name': 'https://www.bouali.io/cves/cve-2021-35976', 'tags': [], 'refsource': 'MISC'}

04 Nov 2021, 01:15

Type Values Removed Values Added
References
  • (MISC) https://www.bouali.io/cves/cve-2021-35976 -

03 Nov 2021, 20:22

Type Values Removed Values Added
References (MISC) https://tarekbouali.com/cves/cve-2021-35976 - (MISC) https://tarekbouali.com/cves/cve-2021-35976 - Exploit, Third Party Advisory

25 Oct 2021, 15:15

Type Values Removed Values Added
References
  • {'url': 'https://tarekbouali.com/cves/cve-2021-35976/', 'name': 'https://tarekbouali.com/cves/cve-2021-35976/', 'tags': ['Exploit', 'Third Party Advisory'], 'refsource': 'MISC'}
  • {'url': 'https://www.bouali.io/cves/cve-2021-35976', 'name': 'https://www.bouali.io/cves/cve-2021-35976', 'tags': ['Broken Link'], 'refsource': 'MISC'}
  • (MISC) https://tarekbouali.com/cves/cve-2021-35976 -

21 Sep 2021, 19:57

Type Values Removed Values Added
CWE CWE-79
CVSS v2 : unknown
v3 : unknown
v2 : 4.3
v3 : 6.1
CPE cpe:2.3:a:plesk:obsidian:*:*:*:*:*:*:*:*
References (MISC) https://tarekbouali.com/cves/cve-2021-35976/ - (MISC) https://tarekbouali.com/cves/cve-2021-35976/ - Exploit, Third Party Advisory
References (MISC) https://www.bouali.io/cves/cve-2021-35976 - (MISC) https://www.bouali.io/cves/cve-2021-35976 - Broken Link
References (MISC) https://support.plesk.com/hc/en-us/articles/4402990507026 - (MISC) https://support.plesk.com/hc/en-us/articles/4402990507026 - Vendor Advisory

14 Sep 2021, 12:15

Type Values Removed Values Added
References
  • (MISC) https://tarekbouali.com/cves/cve-2021-35976/ -

13 Sep 2021, 12:15

Type Values Removed Values Added
Summary The feature to preview a website in Plesk Obsidian 18.0.0 through 18.0.32 on Linux is vulnerable to reflected XSS via the /plesk-site-preview/ PATH, aka PFSI-62467. The attacker could execute JavaScript code in the victim’s browser by using the link to preview sites hosted on the server. Authentication is not required to exploit the vulnerability. The feature to preview a website in Plesk Obsidian 18.0.0 through 18.0.32 on Linux is vulnerable to reflected XSS via the /plesk-site-preview/ PATH, aka PFSI-62467. The attacker could execute JavaScript code in the victim's browser by using the link to preview sites hosted on the server. Authentication is not required to exploit the vulnerability.

10 Sep 2021, 12:44

Type Values Removed Values Added
New CVE

Information

Published : 2021-09-10 12:15

Updated : 2023-12-10 14:09


NVD link : CVE-2021-35976

Mitre link : CVE-2021-35976

CVE.ORG link : CVE-2021-35976


JSON object : View

Products Affected

plesk

  • obsidian
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')