vendor:
Hestia Control Panel
by:
Numan Türle
8.8
CVSS
HIGH
Arbitrary File Write
264
CWE
Product Name: Hestia Control Panel
Affected Version From: < 1.3.3
Affected Version To: 1.3.2
Patch Exists: YES
Related CWE: N/A
CPE: a:hestiacp:hestia_control_panel
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: HestiaCP Version 1.3.2
2021
Hestia Control Panel 1.3.2 – Arbitrary File Write
Hestia Control Panel version 1.3.2 is vulnerable to an arbitrary file write vulnerability. An attacker can exploit this vulnerability by sending a specially crafted POST request to the /api/index.php endpoint with the v-make-tmp-file command and the path of the file to be written. This can be used to write an SSH key to the authorized_keys file, allowing the attacker to gain access to the server.
Mitigation:
Upgrade to Hestia Control Panel version 1.3.3 or later.