CVE-2023-0829
About
Plesk 17.0 through 18.0.31 version, is vulnerable to a Cross-Site Scripting. A malicious subscription owner (either a customer or an additional user), can fully compromise the server if an administrator visits a certain page in Plesk related to the malicious subscription.
Rainforest analyst review
Plesk versions 17.0 through 18.0.31 carry a cross-site scripting flaw where a malicious subscription owner, a customer or an additional user, can plant a payload that fully compromises the server when an administrator later views a certain subscription-related page. It is stored XSS with a devastating endpoint: the attacker starts as a low-privileged tenant and ends with control of the hosting server once an admin's session executes the payload.
The important dynamic is the trust inversion in shared hosting: the attacker only needs a legitimate subscription, something customers are given by design, and then waits for an admin to look at the right page. That makes it very practical in multi-tenant environments where operators routinely review subscriptions, and Plesk's ubiquity on hosting panels makes it a known, worthwhile target. Full server compromise from a tenant account is a serious escalation.
Our angle is chaining and blast radius: on any shared Plesk box, we treat every subscription owner as a potential attacker and prioritize the patch on control panels where untrusted customers hold accounts. Where updating lags, we would tighten admin workflows around viewing untrusted subscriptions and watch for anomalous admin-session behavior, since the exploit hinges on that privileged view firing the payload.
References
Related CVEs
Frequently asked questions
What is CVE-2023-0829?
Plesk 17.0 through 18.0.31 version, is vulnerable to a Cross-Site Scripting. A malicious subscription owner (either a customer or an additional user), can fully compromise the server if an administrator visits a certain page in Plesk related to the malicious subscription.
How severe is CVE-2023-0829?
CVE-2023-0829 carries a CVSS 3.1 base score of 8.8, rated high. On the Rainforest Risk Index — which weighs the severity alongside how easy the flaw is to reach and how broad its impact is — it scores 89 out of 100, in the critical band.
How is CVE-2023-0829 exploited?
According to the CVSS vector (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H): attack vector Network, attack complexity Low, privileges required Low, user interaction None. Impact on confidentiality High, integrity High and availability High.
Which products are affected by CVE-2023-0829?
Public advisories list the following as affected: plesk. Check the references on this page for the exact versions each vendor confirms.
How do I fix CVE-2023-0829?
Apply the fix the vendor published — the references on this page link to the primary advisories and patches. When patching can't happen right away, reduce the exposure of the affected component and watch it for exploitation attempts. Rainforest customers see this vulnerability correlated to their own assets and prioritized by real exposure, not by score alone.
Empower Your Security Strategy with Rainforest
Discover vulnerabilities early, prioritize critical threats, and protect what truly matters. Rainforest streamlines your security operations, saving you time and reducing costs, so you can focus on what drives your business forward.
