Plesk 18.0.79.7 及更早版本,或 18.0.80 至 18.0.80.3 版本中,存在不安全的直接对象引用(IDOR)漏洞。该漏洞允许远程认证用户读取和修改其他客户数据库中的数据。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-65647 | 8.7 HIGH | Plesk 符号链接解析缺陷致 Root 远程代码执行 |
| CVE-2026-65646 | 8.7 HIGH | Plesk 特殊字符处理不当致本地文件泄露及权限提升 |
No comments yet