Description
VestaCP versions prior to 0.9.8-25 contain a cross-site scripting vulnerability in the IP interface configuration that allows attackers to inject malicious scripts. Attackers can exploit the 'v_interface' parameter by sending a crafted POST request to the add/ip/ endpoint with a stored XSS payload.
Problem types
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Product status
Credits
Numan Türle
References
www.exploit-db.com/exploits/49662 (ExploitDB-49662)
vestacp.com (VestaCP Official Vendor Homepage)
myvestacp.com (VestaCP Alternative Download Site)
www.vulncheck.com/...ies/vestacp-stored-cross-site-scripting (VulnCheck Advisory: VestaCP < 0.9.8-25 - Stored Cross-Site Scripting)