vendor:
Plesk SSO
by:
z00
7,5
CVSS
HIGH
XXE Injection
611
CWE
Product Name: Plesk SSO
Affected Version From: 11.0.9
Affected Version To: 10.4.4
Patch Exists: NO
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Linux
2014
Plesk SSO XXE injection (Old bug) Exploit
Plesk SSO XXE injection (Old bug) Exploit is a vulnerability in Plesk SSO which allows an attacker to inject malicious XML code into the application. This exploit was discovered by z00 in 2014 and affects versions 11.0.9 and 10.4.4. It allows an attacker to execute arbitrary commands on the server, read files, and access sensitive information.
Mitigation:
To mitigate XXE injection, applications should disable external entity processing and use a whitelist of allowed entities. Additionally, applications should use a positive security model to ensure that only trusted entities are allowed.