Unauthenticated Access Vulnerability in Plesk Obsidian by Plesk
CVE-2025-49618
5.8MEDIUM
What is CVE-2025-49618?
In Plesk Obsidian 18.0.69, a vulnerability exists that allows unauthenticated users to send requests to the /login_up.php endpoint. This security flaw can expose sensitive AWS credentials including accessKeyId, secretAccessKey, region, and endpoint. Such information can be exploited by attackers to gain unauthorized access or engage in malicious activities, emphasizing the need for immediate updates and security measures to protect users' environments.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Obsidian 18.0.69
References
CVSS V3.1
Score:
5.8
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved
