CVE Feed

    Dashboard / CVE / CVE-2023-24044

    CVE-2023-24044

    A Host Header Injection issue on the Login page of Plesk Obsidian through 18.0.49 allows attackers to redirect users to malicious websites via a Host request header. NOTE: the vendor's position is "the ability to use arbitrary domain names to access the panel is an intended feature."

    Published:Jan 22, 2023
    Last Modified:Apr 2, 2025
    EPS:Jan 22, 2023
    EPSS Score:0.55601
    CVSS Score:6.1

    Affected Products

    Vendor
    Plesk
    Product
    Obsidian

    Common Attack Pattern Enumeration and Classification (CAPEC)

    Related CVEs

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High