CVE-2020-36948

VestaCP 0.9.8-26 contains a session token vulnerability in the LoginAs module that allows remote attackers to manipulate authentication tokens. Attackers can exploit insufficient token validation to access user accounts and perform unauthorized login requests without proper administrative permissions.
Configurations

No configuration.

History

15 Apr 2026, 00:35

Type Values Removed Values Added
Summary
  • (es) VestaCP 0.9.8-26 contiene una vulnerabilidad de token de sesión en el módulo LoginAs que permite a atacantes remotos manipular tokens de autenticación. Los atacantes pueden explotar la validación insuficiente de tokens para acceder a cuentas de usuario y realizar solicitudes de inicio de sesión no autorizadas sin los permisos administrativos adecuados.

27 Jan 2026, 22:15

Type Values Removed Values Added
References () https://www.exploit-db.com/exploits/49219 - () https://www.exploit-db.com/exploits/49219 -
References () https://www.vulnerability-lab.com/get_content.php?id=2240 - () https://www.vulnerability-lab.com/get_content.php?id=2240 -
References () https://www.vulnerability-lab.com/show.php?user=Benjamin%20K.M. - () https://www.vulnerability-lab.com/show.php?user=Benjamin%20K.M. -

27 Jan 2026, 16:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-01-27 16:16

Updated : 2026-04-15 00:35


NVD link : CVE-2020-36948

Mitre link : CVE-2020-36948

CVE.ORG link : CVE-2020-36948


JSON object : View

Products Affected

No product.

CWE
CWE-863

Incorrect Authorization