WebPros Plesk before 18.0.73.5 and 18.0.74 before 18.0.74.2 on Linux allows remote authenticated users to execute arbitrary code as root via domain creation. The attacker needs "Create and manage sites" with "Domains management" and "Subdomains management."
References
Configurations
No configuration.
History
03 Dec 2025, 17:15
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2025-12-03 17:15
Updated : 2025-12-04 17:15
NVD link : CVE-2025-66431
Mitre link : CVE-2025-66431
CVE.ORG link : CVE-2025-66431
JSON object : View
Products Affected
No product.
CWE
CWE-61
UNIX Symbolic Link (Symlink) Following
