CVE-2025-30008: falha de média gravidade em hestiacp
HestiaCP < 1.9.5 Stored XSS via DNS Record Management Interface
Publicada em · Atualizada em
13Vexday Risk Score
Sem sinal de exploração. Nenhum artefato público de exploração conhecido até agora.
ssvc Trackcvss 5.1epss 0.3%
probabilidade de exploração
0.3%top 80% das CVEs
exploração observada
nãonenhuma fonte reporta
HestiaCP before 1.9.5 contains a stored cross-site scripting vulnerability that allows authenticated low-privilege users to inject arbitrary HTML by creating a DNS record with a double-quote followed by a script payload in the value field. The application fails to apply htmlspecialchars() encoding to the DNS record value field rendered into the data-sort-value HTML attribute in list_dns_rec.php, allowing the payload to execute in the browser of any user who views the DNS record list, including administrators.
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N
Produtos afetados
hestiacp · hestiacpCVEs relacionadas — hestiacp
No mesmo produto, das mais perigosas para as menos.
CVE-2025-30007HIGHHestiaCP < 1.9.5 Authenticated OS Command Injection via DNS Record ManagementEPSS 3.2%CVE-2026-43633CRITICALHestiaCP 1.9.0-1.9.4 Deserialization RCE via Web TerminalEPSS 1.5%CVE-2026-12196HIGHHestiaCP Admin TakeoverEPSS 0.4%CVE-2026-43634HIGHHestiaCP 1.2.0-1.9.4 IP Spoofing via CF-Connecting-IP HeaderEPSS 0.4%