Loading HuntDB...

GHSA-8h52-4p7x-v4mc

GitHub Security Advisory

⚠ Unreviewed CRITICAL Has CVE

Advisory Details

In Plesk Obsidian 18.0.70, _isAdminPasswordValid uses an == comparison. Thus, if the correct password is "0e" followed by any digit string, then an attacker can login with any other string that evaluates to 0.0 (such as the 0e0 string). This occurs in admin/plib/LoginManager.php.

Related CVEs

Key Information

GHSA ID
GHSA-8h52-4p7x-v4mc
Published
August 19, 2025 3:31 PM
Last Modified
August 19, 2025 3:31 PM
CVSS Score
9.0 /10
Primary Ecosystem
Unknown
Primary Package
Unknown
GitHub Reviewed
✗ No

Dataset

Last updated: August 23, 2025 6:28 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.