CVE Vulnerabilities

CVE-2011-4749

Published: Dec 16, 2011 | Modified: Apr 11, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
10 HIGH
AV:N/AC:L/Au:N/C:C/I:C/A:C
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

The billing system for Parallels Plesk Panel 10.3.1_build1013110726.09 generates a password form field without disabling the autocomplete feature, which makes it easier for remote attackers to bypass authentication by leveraging an unattended workstation, as demonstrated by forms on certain pages under admin/index.php/default.

Affected Software

NameVendorStart VersionEnd Version
Parallels_plesk_panelParallels10.3.1_build1013110726.09 (including)10.3.1_build1013110726.09 (including)

References