Description
The Parallels Plesk Panel software package is a commercial web hosting automation program. Parallels Plesk Single Sign-On (SSO) technology make it easy for customers to use and manage applications, and reduce the administrative costs of password management for hosting providers. Parallels Plesk Single Sign-On (SSO) implementation was found vulnerable to XXE (XML External Entity) and XSS (Cross-site scripting) vulnerabilities.
Remediation
To disable SSO-mode in Parallels Plesk Panel:
~# /usr/local/psa/bin/sso --disable
References
Related Vulnerabilities
Joomla! Core 2.5.x Cross-Site Scripting (2.5.0 - 2.5.18)
WordPress Plugin WHOIS 'domain' Parameter Cross-Site Scripting (1.4.2.2)
WordPress Plugin Olevmedia Shortcodes Multiple Cross-Site Scripting Vulnerabilities (1.1.9)
WordPress Plugin Spam protection, AntiSpam, FireWall by CleanTalk Cross-Site Scripting (5.113)
WordPress Plugin Cool Flickr Slideshow Cross-Site Scripting (1.0)