GHSA-8h52-4p7x-v4mc
GitHub Security Advisory
⚠ Unreviewed
CRITICAL
Has CVE
Advisory Details
In Plesk Obsidian 18.0.70, _isAdminPasswordValid uses an == comparison. Thus, if the correct password is "0e" followed by any digit string, then an attacker can login with any other string that evaluates to 0.0 (such as the 0e0 string). This occurs in admin/plib/LoginManager.php.
Related CVEs
Key Information
9.0
/10
Dataset
Last updated: August 23, 2025 6:28 AM
Data from GitHub Advisory Database. This information is provided for research and educational purposes.