Description
A Host Header Injection issue on the Login page of Plesk Obsidian through 18.0.49 allows attackers to redirect users to malicious websites via a Host request header.
Remediation
References
Related Vulnerabilities
Plone CMS Permissions, Privileges, and Access Controls Vulnerability (CVE-2013-7061)
WebLogic CVE-2020-2544 Vulnerability (CVE-2020-2544)
Jboss EAP Permissions, Privileges, and Access Controls Vulnerability (CVE-2014-3464)
Elementor Website Builder Cross-Site Scripting (2.9.13)
ownCloud Incorrect Authorization Vulnerability (CVE-2021-29659)