Cobra Forum

Plesk Panel => Others => Topic started by: senthil on Sep 30, 2025, 08:03 AM

Title: Security Alert: CVE-2024-4577 - PHP CGI Argument Injection Vulnerability
Post by: senthil on Sep 30, 2025, 08:03 AM
Situation


Impact

Potentially allow unauthenticated attackers to bypass previous protections and execute arbitrary code on remote
PHP servers through an argument injection attack.

Status

The issue was investigated by our Security Team concluding that Plesk is not affected because:


Therefore Plesk users are not susceptible to this PHP for Windows vulnerability. Nonetheless Plesk PHP versions
will be updated to the corrected ones as usual on its upcoming releases.