Cobra Forum

Plesk Panel => Others => Topic started by: mahesh on Feb 14, 2025, 05:30 AM

Title: CVE-2023-4931: Vulnerability in Plesk Installer
Post by: mahesh on Feb 14, 2025, 05:30 AM
Situation
DLL Hijacking vulnerability was discovered in Plesk Installer (for Windows).

Impact
An attacker can create a malicious DLL file and somehow upload it to the target server. If Plesk Installer is launched from the directory where the malicious DLL is located, malicious commands will be executed.

Call to action
The vulnerability was fixed in Plesk Installer 3.0.55. No additional actions are required.