Vulnerabilities > Vestacp > Control Panel > Critical

DATE CVE VULNERABILITY TITLE RISK
2019-08-15 CVE-2019-12791 Path Traversal vulnerability in Vestacp Control Panel 0.9.824
A directory traversal vulnerability in the v-list-user script in Vesta Control Panel 0.9.8-24 allows remote attackers to escalate from regular registered users to root via the password reset form.
network
low complexity
vestacp CWE-22
critical
9.0
2019-08-15 CVE-2019-12792 OS Command Injection vulnerability in Vestacp Control Panel 0.9.824
A command injection vulnerability in UploadHandler.php in Vesta Control Panel 0.9.8-24 allows remote attackers to escalate from regular registered users to root.
network
low complexity
vestacp CWE-78
critical
9.0