CVE-2021-28379
23Vexday Risk Score
No sign of exploitation. It has a public proof of concept.
ssvc Attendepss 6.0%
from disclosure to weapon2 days
Published on NVDMar 15
1st PoC+2d
exploitation probability
6.0%top 7% of all CVEs
observed exploitation
nono source reports it
2 public exploit(s)
web/upload/UploadHandler.php in Vesta Control Panel (aka VestaCP) through 0.9.8-27 and myVesta through 0.9.8-26-39 allows uploads from a different origin.
Affected products
n/a · n/apublic PoCs found — 2
exploitdbwww.exploit-db.com/exploits/49659unverifiedcve_referencepacketstormsecurity.com/files/161836/VestaCP-0.9.8-Cross-Site-Request-Forgery.htmlunverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.