Vulnerabilities (CVE)

Filtered by vendor Plesk Subscribe
Filtered by product Obsidian
Total 3 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2023-24044 1 Plesk 1 Obsidian 2024-05-17 N/A 6.1 MEDIUM
A Host Header Injection issue on the Login page of Plesk Obsidian through 18.0.49 allows attackers to redirect users to malicious websites via a Host request header. NOTE: the vendor's position is "the ability to use arbitrary domain names to access the panel is an intended feature."
CVE-2021-35976 1 Plesk 1 Obsidian 2024-02-04 4.3 MEDIUM 6.1 MEDIUM
The feature to preview a website in Plesk Obsidian 18.0.0 through 18.0.32 on Linux is vulnerable to reflected XSS via the /plesk-site-preview/ PATH, aka PFSI-62467. The attacker could execute JavaScript code in the victim's browser by using the link to preview sites hosted on the server. Authentication is not required to exploit the vulnerability.
CVE-2020-11583 2 Microsoft, Plesk 2 Windows, Obsidian 2024-02-04 4.3 MEDIUM 6.1 MEDIUM
A GET-based XSS reflected vulnerability in Plesk Obsidian 18.0.17 allows remote unauthenticated users to inject arbitrary JavaScript, HTML, or CSS via a GET parameter.