Description
The Parallels Plesk Panel software package is a commercial web hosting automation program. Parallels Plesk Single Sign-On (SSO) technology make it easy for customers to use and manage applications, and reduce the administrative costs of password management for hosting providers. Parallels Plesk Single Sign-On (SSO) implementation was found vulnerable to XXE (XML External Entity) and XSS (Cross-site scripting) vulnerabilities.
Remediation
To disable SSO-mode in Parallels Plesk Panel:
~# /usr/local/psa/bin/sso --disable
References
Related Vulnerabilities
WordPress Plugin Theme My Login 'instance' Parameter Cross-Site Scripting (6.1.4)
WordPress Plugin Contest Gallery-Photo Contest for WordPress Cross-Site Scripting (13.1.0.9)
WordPress Plugin WP Symposium Pro Social Network Cross-Site Scripting (16.01)
WordPress Plugin Elementor Website Builder Multiple Cross-Site Scripting Vulnerabilities (3.1.1)
WordPress Plugin Custom Sidebars-Dynamic Widget Area Manager Cross-Site Scripting (2.1.0.1)