VYPR
Unrated severityNVD Advisory· Published Feb 21, 2022· Updated Aug 4, 2024

CVE-2021-45008

CVE-2021-45008

Description

Plesk CMS 18.0.37 is affected by an insecure permissions vulnerability that allows privilege Escalation from user to admin rights. OTE: the vendor states that this is only a site-specific problem on websites of one or more Plesk users

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Insecure permissions in Plesk CMS 18.0.37 allow privilege escalation to admin by toggling a 'Super admin flag' parameter.

Vulnerability

Plesk Obsidian 18.0.37 suffers from an insecure permissions vulnerability [1]. The login request contains a Super admin flag parameter that is not properly validated, allowing any authenticated low-privileged user to escalate their role to administrator.

Exploitation

An attacker must have a valid user account with low privileges. The steps are: log in with the low-privileged account, capture the login request using a tool like Burp Suite, observe the Super admin flag parameter set to false, then log out. On the subsequent login attempt, intercept the request, change the Super admin flag parameter to true, and forward the request [1].

Impact

Successful exploitation grants the attacker full administrative rights over the Plesk instance. This includes access to sensitive information such as bank account details and other critical data [1].

Mitigation

The vendor states that this is a site-specific problem for websites of one or more Plesk users. As of the reference publication, no official patch or workaround has been released. Users should review their permission configurations and consider upgrading to a patched version if available. Not yet listed on the CISA Known Exploited Vulnerabilities (KEV) catalog.

AI Insight generated on May 27, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.