#VU26297 Command Injection in Vesta Control Panel - CVE-2020-10808
Published: March 22, 2020 / Updated: April 14, 2020
Vesta Control Panel
Vesta Control Panel
Description
The vulnerability allows a remote user to execute arbitrary commands with elevated privileges.
The vulnerability exists due to insufficient filtration of user-supplied data in schedule/backup Backup Listing Endpoint. A remote user with ability to create a specially crafted filename on the server can execute arbitrary system commands with elevated privileges on the system.