Vulnerability Description
web/upload/UploadHandler.php in Vesta Control Panel (aka VestaCP) through 0.9.8-27 and myVesta through 0.9.8-26-39 allows uploads from a different origin.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Myvestacp | Myvesta | <= 0.9.8-26-39 |
| Vestacp | Vesta Control Panel | <= 0.9.8-27 |
Related Weaknesses (CWE)
References
- http://packetstormsecurity.com/files/161836/VestaCP-0.9.8-Cross-Site-Request-ForExploitThird Party Advisory
- https://github.com/myvesta/vesta/commit/3402071e950e76b79fa8672a1e09b70d3860f355PatchThird Party Advisory
- http://packetstormsecurity.com/files/161836/VestaCP-0.9.8-Cross-Site-Request-ForExploitThird Party Advisory
- https://github.com/myvesta/vesta/commit/3402071e950e76b79fa8672a1e09b70d3860f355PatchThird Party Advisory
FAQ
What is CVE-2021-28379?
CVE-2021-28379 is a vulnerability with a CVSS score of 8.8 (HIGH). web/upload/UploadHandler.php in Vesta Control Panel (aka VestaCP) through 0.9.8-27 and myVesta through 0.9.8-26-39 allows uploads from a different origin.
How severe is CVE-2021-28379?
CVE-2021-28379 has been rated HIGH with a CVSS base score of 8.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2021-28379?
Check the references section above for vendor advisories and patch information. Affected products include: Myvestacp Myvesta, Vestacp Vesta Control Panel.