Cross-Site Scripting Vulnerability in Parallels Plesk Panel
CVE-2011-4850

Currently unrated

Key Information:

Vendor

Parallels

Vendor
CVE Published:
16 December 2011

What is CVE-2011-4850?

The Control Panel in Parallels Plesk Panel version 10.4.4_build20111103.18 lacks the HTTPOnly flag in Set-Cookie headers, which exposes cookies to potential script access by remote attackers. This vulnerability enables attackers to access sensitive information stored in cookies, increasing the risk of unauthorized actions and data breaches.

References

Timeline

  • Vulnerability Reserved

  • Vulnerability published

.