Description
The Parallels Plesk Panel software package is a commercial web hosting automation program. Parallels Plesk Single Sign-On (SSO) technology make it easy for customers to use and manage applications, and reduce the administrative costs of password management for hosting providers. Parallels Plesk Single Sign-On (SSO) implementation was found vulnerable to XXE (XML External Entity) and XSS (Cross-site scripting) vulnerabilities.
Remediation
To disable SSO-mode in Parallels Plesk Panel:
~# /usr/local/psa/bin/sso --disable
References
Related Vulnerabilities
WordPress Plugin Slimstat Analytics Cross-Site Scripting (3.5.5)
WordPress Plugin Ultimate Affiliate Pro Multiple Cross-Site Scripting Vulnerabilities (3.6)
WordPress Plugin cformsII Multiple Cross-Site Scripting Vulnerabilities (14.13.2)
WordPress Plugin Photo Gallery by 10Web-Mobile-Friendly Image Gallery Cross-Site Scripting (1.5.78)
WordPress Plugin Export User Data Cross-Site Scripting (1.3.1)