Description
A GET-based XSS reflected vulnerability in Plesk Obsidian 18.0.17 allows remote unauthenticated users to inject arbitrary JavaScript, HTML, or CSS via a GET parameter.
Remediation
References
Related Vulnerabilities
WordPress Plugin Accept Stripe Donation-AidWP Cross-Site Request Forgery (3.1.5)
Drupal Deserialization of Untrusted Data Vulnerability (CVE-2019-6338)
Apache HTTP Server Other Vulnerability (CVE-2002-2012)
Oracle Database Server CVE-2014-6455 Vulnerability (CVE-2014-6455)
Django Permissions, Privileges, and Access Controls Vulnerability (CVE-2014-0473)