Home Embedded Vulns General Vulns

CVE-2020-10966

MEDIUM 6.5

Our Analysis: General Purpose

Our model has classified this vulnerability as relevant to General Purpose Systems, helping your team prioritize efforts effectively.

Published Date March 25, 2020
Last Modified November 21, 2024
CVSS Vector Not Available

Description

In the Password Reset Module in VESTA Control Panel through 0.9.8-25 and Hestia Control Panel before 1.1.1, Host header manipulation leads to account takeover because the victim receives a reset URL containing an attacker-controlled server name.

Potentially Affected Vendors