CVE Vulnerabilities

CVE-2025-49618

Transmission of Private Resources into a New Sphere ('Resource Leak')

Published: Jul 03, 2025 | Modified: Jul 03, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

In Plesk Obsidian 18.0.69, unauthenticated requests to /login_up.php can reveal an AWS accessKeyId, secretAccessKey, region, and endpoint.

Weakness

The product makes resources available to untrusted parties when those resources are only intended to be accessed by the product.

References