Description
A Host Header Injection issue on the Login page of Plesk Obsidian through 18.0.49 allows attackers to redirect users to malicious websites via a Host request header.
Remediation
References
Related Vulnerabilities
Zenphoto Unrestricted Upload of File with Dangerous Type Vulnerability (CVE-2020-36079)
MySQL CVE-2022-21320 Vulnerability (CVE-2022-21320)
WordPress Plugin UpdraftPlus WordPress Backup Security Bypass (1.9.50)
WordPress Plugin Photo Gallery by 10Web-Mobile-Friendly Image Gallery Cross-Site Scripting (1.2.12)