Unauthenticated Access Vulnerability in Plesk Obsidian by Plesk
CVE-2025-49618

5.8MEDIUM

Key Information:

Vendor

Plesk

Status
Vendor
CVE Published:
3 July 2025

What is CVE-2025-49618?

In Plesk Obsidian 18.0.69, a vulnerability exists that allows unauthenticated users to send requests to the /login_up.php endpoint. This security flaw can expose sensitive AWS credentials including accessKeyId, secretAccessKey, region, and endpoint. Such information can be exploited by attackers to gain unauthorized access or engage in malicious activities, emphasizing the need for immediate updates and security measures to protect users' environments.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

Obsidian 18.0.69

References

CVSS V3.1

Score:
5.8
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.