Medium severity6.1OSV Advisory· Published May 6, 2018· Updated Jun 17, 2026
CVE-2018-10686
CVE-2018-10686
Description
An issue was discovered in Vesta Control Panel 0.9.8-20. There is Reflected XSS via $_REQUEST['path'] to the view/file/index.php URI, which can lead to remote PHP code execution via vectors involving a file_put_contents call in web/upload/UploadHandler.php.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
20.9.8-10, 0.9.8-11, 0.9.8-12, …+ 1 more
- (no CPE)range: 0.9.8-10, 0.9.8-11, 0.9.8-12, …
- (no CPE)range: = 0.9.8-20
Patches
Vulnerability mechanics
References
2- github.com/serghey-rodin/vesta/issues/1558nvdExploitThird Party Advisory
- medium.com/%40ndrbasi/cve-2018-10686-vestacp-rce-d96d95c2bde2nvd
News mentions
0No linked articles in our index yet.