Vulnerabilities > Vestacp > Vesta Control Panel > Medium

DATE CVE VULNERABILITY TITLE RISK
2022-07-19 CVE-2022-34025 Cross-site Scripting vulnerability in Vestacp Vesta Control Panel 1.0.05
Vesta v1.0.0-5 was discovered to contain a cross-site scripting (XSS) vulnerability via the post function at /web/api/v1/upload/UploadHandler.php.
network
low complexity
vestacp CWE-79
6.1
2022-07-19 CVE-2022-36303 Cross-site Scripting vulnerability in Vestacp Vesta Control Panel 1.0.05
Vesta v1.0.0-5 was discovered to contain a cross-site scripting (XSS) vulnerability via the handle_file_upload function at /web/api/v1/upload/UploadHandler.php.
network
low complexity
vestacp CWE-79
6.1
2022-07-19 CVE-2022-36304 Cross-site Scripting vulnerability in Vestacp Vesta Control Panel 1.0.05
Vesta v1.0.0-5 was discovered to contain a cross-site scripting (XSS) vulnerability via the generate_response function at /web/api/v1/upload/UploadHandler.php.
network
low complexity
vestacp CWE-79
6.1
2022-07-19 CVE-2022-36305 Cross-site Scripting vulnerability in Vestacp Vesta Control Panel 1.0.05
Vesta v1.0.0-5 was discovered to contain a cross-site scripting (XSS) vulnerability via the body function at /web/api/v1/upload/UploadHandler.php.
network
low complexity
vestacp CWE-79
6.1