CVE-2021-45007

Plesk 18.0.37 is affected by a Cross Site Request Forgery (CSRF) vulnerability that allows an attacker to insert data on the user and admin panel. NOTE: the vendor states that this is only a site-specific problem on websites of one or more Plesk users
References
Link Resource
https://github.com/AS4mir/CVE-2021-45007/blob/main/README.md Exploit Third Party Advisory
Configurations

Configuration 1 (hide)

cpe:2.3:a:plesk:plesk:18.0.37:*:*:*:*:*:*:*

History

07 Nov 2023, 03:39

Type Values Removed Values Added
Summary ** DISPUTED ** Plesk 18.0.37 is affected by a Cross Site Request Forgery (CSRF) vulnerability that allows an attacker to insert data on the user and admin panel. NOTE: the vendor states that this is only a site-specific problem on websites of one or more Plesk users. Plesk 18.0.37 is affected by a Cross Site Request Forgery (CSRF) vulnerability that allows an attacker to insert data on the user and admin panel. NOTE: the vendor states that this is only a site-specific problem on websites of one or more Plesk users

01 Mar 2022, 23:32

Type Values Removed Values Added
CWE CWE-352
References (MISC) https://github.com/AS4mir/CVE-2021-45007/blob/main/README.md - (MISC) https://github.com/AS4mir/CVE-2021-45007/blob/main/README.md - Exploit, Third Party Advisory
CPE cpe:2.3:a:plesk:plesk:18.0.37:*:*:*:*:*:*:*
CVSS v2 : unknown
v3 : unknown
v2 : 4.3
v3 : 6.5
First Time Plesk
Plesk plesk

24 Feb 2022, 15:15

Type Values Removed Values Added
Summary Plesk 18.0.37 is affected by a Cross Site Request Forgery (CSRF) vulnerability that allows an attacker to insert data on the user and admin panel. ** DISPUTED ** Plesk 18.0.37 is affected by a Cross Site Request Forgery (CSRF) vulnerability that allows an attacker to insert data on the user and admin panel. NOTE: the vendor states that this is only a site-specific problem on websites of one or more Plesk users.
References
  • {'url': 'http://plesk.com', 'name': 'http://plesk.com', 'tags': [], 'refsource': 'MISC'}

20 Feb 2022, 12:15

Type Values Removed Values Added
New CVE

Information

Published : 2022-02-20 12:15

Updated : 2024-05-17 02:02


NVD link : CVE-2021-45007

Mitre link : CVE-2021-45007

CVE.ORG link : CVE-2021-45007


JSON object : View

Products Affected

plesk

  • plesk
CWE
CWE-352

Cross-Site Request Forgery (CSRF)