Medium severity6.5NVD Advisory· Published Mar 25, 2020· Updated Jun 17, 2026
CVE-2020-10966
CVE-2020-10966
Description
In the Password Reset Module in VESTA Control Panel through 0.9.8-25 and Hestia Control Panel before 1.1.1, Host header manipulation leads to account takeover because the victim receives a reset URL containing an attacker-controlled server name.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3- VESTA/VESTA Control Paneldescription
- Range: <=0.9.8-25
Patches
Vulnerability mechanics
References
3- github.com/serghey-rodin/vesta/commit/c3c4de43d6701560f604ca7996f717b08e3d7d1dnvdPatchThird Party Advisory
- github.com/hestiacp/hestiacp/issues/748nvdExploitThird Party Advisory
- github.com/hestiacp/hestiacp/releases/tag/1.1.1nvdThird Party Advisory
News mentions
0No linked articles in our index yet.