关键漏洞信息 CVE-ID: CVE-2025-65518 Reporter: Jainil Borisagar Title: Denial of Service Vulnerability in Plesk Obsidian via get_password.php Description: Plesk Obsidian versions 8.0.1 through 18.0.73 are vulnerable to Denial of Service (DoS). The vulnerability exists in the get_password.php endpoint, causing a crafted request to continuously reload the web interface and render the service unavailable to legitimate users. Affected Product: - Vendor: Plesk - Product: Plesk Obsidian - Affected Versions: 8.0.1 to 18.0.73 Vulnerability Type: Denial of Service (DoS) Affected Component: get_password.php endpoint in Plesk Obsidian authentication interface Attack Vector: A crafted request sends the page into an infinite reload loop, making the service inaccessible. CVSS Score: - CVSS Version: 3.1 - Base Score: 7.5 (High) - Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Plesk Advisory: PPPM-15164 Steps to Reproduce: 1. Access a Plesk Obsidian instance within affected versions. 2. Send a crafted request to get_password.php with a malicious payload. 3. Observe the continuous reloading of the web interface. Vendor Acknowledgement: Confirmed and Acknowledged