Password Reset Vulnerability in VESTA Control Panel and Hestia Control Panel
CVE-2020-10966
6.5MEDIUM
What is CVE-2020-10966?
A security flaw exists in the Password Reset Module of VESTA Control Panel and Hestia Control Panel, where attackers can exploit host header manipulation. This vulnerability allows an attacker to craft a malicious reset password URL. When the victim interacts with this link, it directs them to an attacker-controlled server, potentially leading to unauthorized account access and takeover.
