CVE-2020-10808 is a critical command injection vulnerability affecting Vesta Control Panel (VestaCP) versions through 0.9.8-26. An authenticated attacker can exploit this by crafting a malicious filename, typically through an FTP session, which is then processed by the schedule/backup Backup Listing Endpoint. This vulnerability carries a high CVSS score of 8.8, indicating a severe risk with high impact on confidentiality, integrity, and availability, requiring only low privileges and no user interaction. While not currently on the CISA KEV catalog, a Metasploit module exists for authenticated remote code execution, and its high EPSS score suggests a significant likelihood of exploitation. Despite the availability of exploit code, there is minimal community discussion or media coverage surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 0.9.8-26CPE matchmatch criteria | cpe:2.3:a:vestacp:vesta_control_panel:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.