CVE-2023-4931

Uncontrolled search path element vulnerability in Plesk Installer affects version 3.27.0.0. A local attacker could execute arbitrary code by injecting DLL files into the same folder where the application is installed, resulting in DLL hijacking in edputil.dll, samlib.dll, urlmon.dll, sspicli.dll, propsys.dll and profapi.dll files.
Configurations

Configuration 1 (hide)

cpe:2.3:a:plesk:plesk:3.27.0.0:*:*:*:*:*:*:*

History

No history.

Information

Published : 2023-11-27 14:15

Updated : 2023-12-01 19:06


NVD link : CVE-2023-4931

Mitre link : CVE-2023-4931

CVE.ORG link : CVE-2023-4931


JSON object : View

Products Affected

plesk

  • plesk
CWE
CWE-427

Uncontrolled Search Path Element