Cross-site scripting in Hestia Control Panel - #VU140559

 

Cross-site scripting in Hestia Control Panel - #VU140559

Published: July 30, 2026


Vulnerability identifier: #VU140559
CSH Severity: Low
CVSS v4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N]
CVE-ID: N/A
CWE-ID: CWE-79
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to execute arbitrary JavaScript in an administrator context and gain access to administrator functions.

The vulnerability exists due to cross-site scripting in the SSL certificate handling functionality when processing crafted self-signed certificate data in site settings. A remote user can inject a crafted script through certificate fields to execute arbitrary JavaScript in an administrator context and gain access to administrator functions.

User interaction is required because an administrator must open the affected site settings page after logging in as the target user.


Affected software

Hestia Control Panel

Remediation

Install security update from vendor's website.

Hestia Control Panel - update to 1.9.5

External References

Related Security Bulletins