kb: security
Situation
A blind SQL injection vulnerability was discovered in Plesk.
Affected product version
| Product | Affected versions | Patched versions |
|---|---|---|
| Plesk for Linux | 18.0.51 - 18.0.80 | 18.0.80.1 and 18.0.79.5 |
| Plesk for Windows | 18.0.80 and earlier | 18.0.80.1 and 18.0.79.5 |
How to verify that a server is patched
You can confirm your installed Plesk version and build using the Plesk interface:
- Log in to Plesk.
- In the left sidebar, go to Tools & Settings.
- Under Plesk, click About Plesk.
- The currently installed Plesk version is displayed under the logo (for example, "Version 18.0.79 Update #5").
- Compare the displayed build to the patched version in the table above. If an earlier version is shown, the server should be updated.
Impact
An attacker could extract data from the server's database with a read-only SQL injection.
Call to action
Update Plesk to the latest build: How to update Plesk Obsidian to the latest build
Mitigation
If you are unable to update immediately, you can reduce risk from this issue by either of the following:
- Disabling OS-level system logins for resellers by setting
systemAdmin = offunder the[login]section of Panel.ini. - Disabling API access for reseller accounts via the relevant service plan permission.
We strongly recommend updating the latest hotfix version as soon as possible.
Please reach out to our support team if you have any questions or need further guidance.
Acknowledgement
We would like to thank Aziz Knani for responsibly disclosing this vulnerability.
Comments
Hi! Could you please clarify whether exploitation of this vulnerability requires an authenticated reseller account, or whether users with lower privileges (e.g. customer accounts) could also exploit it?
The mitigation section seems to imply that reseller-level access is required, but this is not explicitly stated in the advisory.
We would also like to know the answer to Amalfiweb 's question!
Please sign in to leave a comment.