VYPR
High severity7.2NVD Advisory· Published Oct 24, 2022· Updated Jun 17, 2026

CVE-2021-46850

CVE-2021-46850

Description

myVesta Control Panel before 0.9.8-26-43 and Vesta Control Panel before 0.9.8-26 are vulnerable to command injection. An authenticated and remote administrative user can execute arbitrary commands via the v_sftp_license parameter when sending HTTP POST requests to the /edit/server endpoint.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

5
  • cpe:2.3:a:vestacp:control_panel:*:*:*:*:*:*:*:*
    Range: <0.9.8-26-43
  • cpe:2.3:a:vestacp:vesta_control_panel:*:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:vestacp:vesta_control_panel:*:*:*:*:*:*:*:*range: <0.9.8-26
    • (no CPE)range: <0.9.8-26
  • myVesta Control Panel/myVesta Control Paneldescription
  • Range: <0.9.8-26-43

Patches

Vulnerability mechanics

References

5

News mentions

0

No linked articles in our index yet.