CVE-2025-66430 — Plesk 18.0 has Incorrect Access Control.
Plesk 18.0 has Incorrect Access Control.
Plesk 18.0 has Incorrect Access Control.
Plesk 18.0 has Incorrect Access Control.
CVE-2025-66430CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:NStatic Code Injection in Plesk extensions "Ruby" before 1.6.6 and "Node.js Toolkit" before 2.5.0 allows remote authenticated users to execute arbitrary code as root via custom environment variables.
Improper neutralization of special elements in Plesk allows remote authenticated users to disclose arbitrary local files and escalate privileges.
Improper symlink resolution before file access in Plesk allows remote authenticated users to execute arbitrary code as root.