CVE-2025-66431

WebPros Plesk before 18.0.73.5 and 18.0.74 before 18.0.74.2 on Linux allows remote authenticated users to execute arbitrary code as root via domain creation. The attacker needs "Create and manage sites" with "Domains management" and "Subdomains management."
Configurations

No configuration.

History

03 Dec 2025, 17:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-12-03 17:15

Updated : 2025-12-04 17:15


NVD link : CVE-2025-66431

Mitre link : CVE-2025-66431

CVE.ORG link : CVE-2025-66431


JSON object : View

Products Affected

No product.

CWE
CWE-61

UNIX Symbolic Link (Symlink) Following