CVE-2021-46850
HIGH EXPLOITEDmyVesta Control Panel <0.9.8-26-43 - Command Injection
Title source: llmDescription
myVesta Control Panel before 0.9.8-26-43 and Vesta Control Panel before 0.9.8-26 are vulnerable to command injection. An authenticated and remote administrative user can execute arbitrary commands via the v_sftp_license parameter when sending HTTP POST requests to the /edit/server endpoint.
Exploits (1)
exploitdb
WORKING POC
by numan türle · textwebappsmultiple
https://www.exploit-db.com/exploits/49674
References (5)
Scores
CVSS v3
7.2
EPSS
0.1245
EPSS Percentile
93.9%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
total
Details
VulnCheck KEV
2021-06-03
CWE
CWE-88
Status
published
Products (2)
vestacp/control_panel
< 0.9.8-26-43
vestacp/vesta_control_panel
< 0.9.8-26
Published
Oct 24, 2022
Tracked Since
Feb 18, 2026