Cross-Site Scripting Vulnerability in Parallels Plesk Panel
CVE-2011-4777
Currently unrated
What is CVE-2011-4777?
A cross-site scripting (XSS) vulnerability exists in the Site Editor feature of Parallels Plesk Panel 10.4.4_build20111103.18. This allows remote attackers to inject and execute arbitrary web scripts or HTML. The attack is executed via the login parameter to the preferences.html page, potentially compromising the integrity of users' sessions and sensitive data. Organizations using this version should implement security measures to mitigate the risk of exploitation.
References
Timeline
Vulnerability Reserved
Vulnerability published