Vulnerability Description
Vesta Control Panel (VestaCP) through 0.9.8-26 allows Command Injection via the schedule/backup Backup Listing Endpoint. The attacker must be able to create a crafted filename on the server, as demonstrated by an FTP session that renames .bash_logout to a .bash_logout' substring followed by shell metacharacters.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Vestacp | Vesta Control Panel | <= 0.9.8-26 |
Related Weaknesses (CWE)
References
- http://packetstormsecurity.com/files/157111/Vesta-Control-Panel-Authenticated-ReExploitThird Party AdvisoryVDB Entry
- http://packetstormsecurity.com/files/157219/Vesta-Control-Panel-Authenticated-ReExploitThird Party AdvisoryVDB Entry
- https://forum.vestacp.com/viewforum.php?f=25Release NotesVendor Advisory
- https://github.com/rapid7/metasploit-framework/pull/13094PatchThird Party Advisory
- https://pentest.blog/vesta-control-panel-second-order-remote-code-execution-0dayExploitThird Party Advisory
- http://packetstormsecurity.com/files/157111/Vesta-Control-Panel-Authenticated-ReExploitThird Party AdvisoryVDB Entry
- http://packetstormsecurity.com/files/157219/Vesta-Control-Panel-Authenticated-ReExploitThird Party AdvisoryVDB Entry
- https://forum.vestacp.com/viewforum.php?f=25Release NotesVendor Advisory
- https://github.com/rapid7/metasploit-framework/pull/13094PatchThird Party Advisory
- https://pentest.blog/vesta-control-panel-second-order-remote-code-execution-0dayExploitThird Party Advisory
FAQ
What is CVE-2020-10808?
CVE-2020-10808 is a vulnerability with a CVSS score of 8.8 (HIGH). Vesta Control Panel (VestaCP) through 0.9.8-26 allows Command Injection via the schedule/backup Backup Listing Endpoint. The attacker must be able to create a crafted filename on the server, as demons...
How severe is CVE-2020-10808?
CVE-2020-10808 has been rated HIGH with a CVSS base score of 8.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2020-10808?
Check the references section above for vendor advisories and patch information. Affected products include: Vestacp Vesta Control Panel.