CVE-2023-4931

Uncontrolled search path element vulnerability in Plesk Installer affects version 3.27.0.0. A local attacker could execute arbitrary code by injecting DLL files into the same folder where the application is installed, resulting in DLL hijacking in edputil.dll, samlib.dll, urlmon.dll, sspicli.dll, propsys.dll and profapi.dll files.
Configurations

Configuration 1 (hide)

cpe:2.3:a:plesk:plesk:3.27.0.0:*:*:*:*:*:*:*

History

01 Dec 2023, 19:06

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.8
First Time Plesk
Plesk plesk
CPE cpe:2.3:a:plesk:plesk:3.27.0.0:*:*:*:*:*:*:*
References () https://support.plesk.com/hc/en-us/articles/17426121182103 - () https://support.plesk.com/hc/en-us/articles/17426121182103 - Vendor Advisory
References () https://www.incibe.es/en/incibe-cert/notices/aviso/uncontrolled-search-path-element-vulnerability-plesk - () https://www.incibe.es/en/incibe-cert/notices/aviso/uncontrolled-search-path-element-vulnerability-plesk - Third Party Advisory

30 Nov 2023, 14:15

Type Values Removed Values Added
References
  • () https://support.plesk.com/hc/en-us/articles/17426121182103 -

27 Nov 2023, 14:15

Type Values Removed Values Added
New CVE

Information

Published : 2023-11-27 14:15

Updated : 2024-02-28 20:54


NVD link : CVE-2023-4931

Mitre link : CVE-2023-4931

CVE.ORG link : CVE-2023-4931


JSON object : View

Products Affected

plesk

  • plesk
CWE
CWE-427

Uncontrolled Search Path Element