CVE-2021-46850
HIGH EXPLOITEDmyVesta Control Panel <0.9.8-26-43 - Command Injection
Title source: llmDescription
myVesta Control Panel before 0.9.8-26-43 and Vesta Control Panel before 0.9.8-26 are vulnerable to command injection. An authenticated and remote administrative user can execute arbitrary commands via the v_sftp_license parameter when sending HTTP POST requests to the /edit/server endpoint.
Exploits (1)
exploitdb
WORKING POC
by numan türle · textwebappsmultiple
https://www.exploit-db.com/exploits/49674
References (5)
Scores
CVSS v3
7.2
EPSS
0.1558
EPSS Percentile
94.6%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Exploitation Intel
VulnCheck KEV
2021-06-03
Classification
CWE
CWE-88
Status
published
Affected Products (2)
vestacp/control_panel
< 0.9.8-26-43
vestacp/vesta_control_panel
< 0.9.8-26
Timeline
Published
Oct 24, 2022
Tracked Since
Feb 18, 2026