Cross-Site Scripting Vulnerability in Parallels Plesk Panel
CVE-2011-4777

Currently unrated

Key Information:

Vendor

Parallels

Vendor
CVE Published:
16 December 2011

What is CVE-2011-4777?

A cross-site scripting (XSS) vulnerability exists in the Site Editor feature of Parallels Plesk Panel 10.4.4_build20111103.18. This allows remote attackers to inject and execute arbitrary web scripts or HTML. The attack is executed via the login parameter to the preferences.html page, potentially compromising the integrity of users' sessions and sensitive data. Organizations using this version should implement security measures to mitigate the risk of exploitation.

References

Timeline

  • Vulnerability Reserved

  • Vulnerability published

.