漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
HestiaCP Admin Takeover
Vulnerability Description
HestiaCP panel cronjob feature is affected by a broken access control vulnerability. Low privilege users can modify the panel cronjob to execute scripts HestiaCP management scripts with passwordless sudo. This could result in the takeover of administrator users in the application and the underlying webserver.
CVSS Information
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N
Vulnerability Type
认证机制不恰当
Vulnerability Title
HestiaCP 授权问题漏洞
Vulnerability Description
HestiaCP是HestiaCP团队开源的一款轻量级控制面板。 HestiaCP存在授权问题漏洞,该漏洞源于访问控制不当,低权限用户可修改面板计划任务以执行HestiaCP管理脚本,这可能导致管理员用户和底层Web服务器被接管。
CVSS Information
N/A
Vulnerability Type
N/A