在访问文件之前,Plesk 中存在符号链接(symlink)解析不当的问题,这使得远程已认证用户能够以 root 身份执行任意代码。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| WebPros | Plesk Migrator | 0 ~ 2.36.0 | - |
|
| WebPros | Plesk Site Import | 0 ~ 1.12.1 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-65646 | 8.7 HIGH | Plesk 特殊字符处理不当致本地文件泄露及权限提升 |
| CVE-2026-65642 | 8.6 HIGH | Plesk 18.0.79.7及18.0.80.3前存在IDOR漏洞 |
No comments yet