Authenticated Command Execution Vulnerability in Vesta Control Panel by VestaCP
CVE-2019-9859
8.8HIGH
What is CVE-2019-9859?
The Vesta Control Panel (VestaCP) versions 0.9.7 through 0.9.8-23 are vulnerable to an authenticated command execution flaw that can allow attackers to gain remote root access. This occurs through improper handling of user inputs when executing shell commands, specifically via the PHP exec function. Although the escapeshellarg function is intended to secure user inputs by wrapping strings in quotes, it has been misapplied in several instances within VestaCP. This misconfiguration can lead to potential exploitation, making it critically important for users of these versions to apply appropriate security measures.
