CVE-2021-46850

HIGH EXPLOITED

myVesta Control Panel <0.9.8-26-43 - Command Injection

Title source: llm

Description

myVesta Control Panel before 0.9.8-26-43 and Vesta Control Panel before 0.9.8-26 are vulnerable to command injection. An authenticated and remote administrative user can execute arbitrary commands via the v_sftp_license parameter when sending HTTP POST requests to the /edit/server endpoint.

Exploits (1)

exploitdb WORKING POC
by numan türle · textwebappsmultiple
https://www.exploit-db.com/exploits/49674

Scores

CVSS v3 7.2
EPSS 0.1558
EPSS Percentile 94.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

Exploitation Intel

VulnCheck KEV 2021-06-03

Classification

CWE
CWE-88
Status published

Affected Products (2)

vestacp/control_panel < 0.9.8-26-43
vestacp/vesta_control_panel < 0.9.8-26

Timeline

Published Oct 24, 2022
Tracked Since Feb 18, 2026