GHSA-pgxq-gj96-mq7gHighCVSS 7.5
Plesk Obsidian versions 8.0.1 through 18.0.73 are vulnerable to a Denial of Service (DoS)...
🔗 CVE IDs covered (1)
📋 Description
Plesk Obsidian versions 8.0.1 through 18.0.73 are vulnerable to a Denial of Service (DoS) condition. The vulnerability exists in the get_password.php endpoint, where a crafted request containing a malicious payload can cause the affected web interface to continuously reload, rendering the service unavailable to legitimate users. An attacker can exploit this issue remotely without authentication, resulting in a persistent availability impact on the affected Plesk Obsidian instance.
🔗 References (8)
- https://nvd.nist.gov/vuln/detail/CVE-2025-65518
- https://docs.plesk.com/release-notes/obsidian/change-log
- https://github.com/Jainil-89/CVE-2025-65518/blob/main/cve.md
- http://plesk.com
- https://access.redhat.com/security/cve/CVE-2025-65518
- https://bugzilla.redhat.com/show_bug.cgi?id=2428098
- https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-65518.json
- https://github.com/advisories/GHSA-pgxq-gj96-mq7g