漏洞描述
Plesk Obsidian through 18.0.49 contains an open redirect vulnerability via the login page. An attacker can redirect users to malicious websites via a host request header and thereby access user credentials and execute unauthorized operations. NOTE: The vendor's position is "the ability to use arbitrary domain names to access the panel is an intended feature."
影响产品
修复建议
建议关注厂商安全公告,及时升级至已修复版本,并结合实际资产暴露情况采取缓解措施。
参考链接
medium.comhttps://medium.com/@jetnipat.tho/cve-2023-24044-10e48ab940d8↗gist.github.comhttps://gist.github.com/TJetnipat/02b3854543b7ec95d54a8de811f2e8ae↗nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2023-24044↗support.plesk.comhttps://support.plesk.com/hc/en-us/articles/10254625170322-Vulnerability-CVE-2023-24044↗