CVE-2023-5839 describes a privilege chaining vulnerability in Hestia Control Panel versions prior to 1.8.9. This flaw allows a local, low-privileged attacker to escalate their privileges, potentially leading to full compromise of the affected system (CVSS 7.8 HIGH). While no public exploits, Metasploit modules, or Nuclei templates are currently available, and there's no evidence of active exploitation or significant community discussion, the high severity warrants prompt patching.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.8.9CPE matchmatch criteria | cpe:2.3:a:hestiacp:control_panel:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.