CVE-2021-27231

Published

Severity

CVSS v3:
5.4 MEDIUM
CVSS v2:
5.5 MEDIUM

Description

Hestia Control Panel 1.3.5 and below, in a shared-hosting environment, sometimes allows remote authenticated users to create a subdomain for a different customer's domain name, leading to spoofing of services or email messages.

References

Configurations

CPE23Version StartVersion EndExact Version
cpe:2.3:a:hestiacp:control_panel:*:*:*:*:*:*:*:*n/a1.3.5 (including)*

External Links