Cross-Domain Referer Leakage in Parallels Plesk Panel
CVE-2011-4852

Currently unrated

Key Information:

Vendor

Parallels

Vendor
CVE Published:
16 December 2011

What is CVE-2011-4852?

The Control Panel in Parallels Plesk Panel 10.4.4_build20111103.18 is vulnerable to cross-domain Referer leakage, where web pages with external links are generated for specific GET requests. This flaw enables remote attackers to potentially harvest sensitive information by analyzing web-server access logs or Referer logs, thus exposing users to privacy risks. It is crucial to address this issue to prevent unauthorized access to sensitive user data.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.