Cobra Forum

Plesk Panel => Others => Topic started by: mahesh on Jan 27, 2025, 05:44 AM

Title: Security Alert: CVE-2024-4577 - PHP CGI Argument Injection Vulnerability
Post by: mahesh on Jan 27, 2025, 05:44 AM
Situation
Critical vulnerability CVE-2024-4577 has been identified in PHP, affecting all versions of PHP installed on the Windows operating systems below the next:

Impact
Potentially allow unauthenticated attackers to bypass previous protections and execute arbitrary code on remote PHP servers through an argument injection attack.

Status
The issue was investigated by our Security Team concluding that Plesk is not affected because:

Therefore Plesk users are not susceptible to this PHP for Windows vulnerability. Nonetheless Plesk PHP versions will be updated to the corrected ones as usual on its upcoming releases.