VulnerabilityModified
CVE-2020-10966
In the Password Reset Module in VESTA Control Panel through 0.9.8-25 and Hestia Control Panel before 1.1.1, Host header manipulation leads to account takeover because the victim receives a reset URL containing an attacker-controlled server name.
MEDIUM 6.5EPSS 1.85%
Does this matter?
Lower severity and a low EPSS score (1.85%). Track it; it rarely justifies an emergency change on its own.
Description
In the Password Reset Module in VESTA Control Panel through 0.9.8-25 and Hestia Control Panel before 1.1.1, Host header manipulation leads to account takeover because the victim receives a reset URL containing an attacker-controlled server name.
- CVSS 3.1
- 6.5 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
- EPSS
- 1.85% probability · 78th percentile
- CISA KEV
- Not listed
- Affected
- hestiacp/control panel · vestacp/control panel
- Source
- cve@mitre.org
References
- https://github.com/hestiacp/hestiacp/issues/748Exploit, Third Party Advisory
- https://github.com/hestiacp/hestiacp/releases/tag/1.1.1Third Party Advisory
- https://github.com/serghey-rodin/vesta/commit/c3c4de43d6701560f604ca7996f717b08e3d7d1dPatch, Third Party Advisory
- https://github.com/hestiacp/hestiacp/issues/748Exploit, Third Party Advisory
- https://github.com/hestiacp/hestiacp/releases/tag/1.1.1Third Party Advisory
- https://github.com/serghey-rodin/vesta/commit/c3c4de43d6701560f604ca7996f717b08e3d7d1dPatch, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.