VYPR
Medium severity6.5NVD Advisory· Published Nov 10, 2022· Updated Jun 17, 2026

CVE-2022-45130

CVE-2022-45130

Description

Plesk Obsidian allows a CSRF attack, e.g., via the /api/v2/cli/commands REST API to change an Admin password. NOTE: Obsidian is a specific version of the Plesk product: version numbers were used through version 12, and then the convention was changed so that versions are identified by names ("Obsidian"), not numbers.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

3
  • Plesk/Obsidian2 versions
    cpe:2.3:a:plesk:obsidian:-:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:plesk:obsidian:-:*:*:*:*:*:*:*
    • (no CPE)
  • Plesk/Pleskdescription

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.