Plesk Obsidian: PHP 8.3 and enhanced WAF rules support
New micro-release; comes with PHP 8.3 handler support and updated Comodo/Atomicorp WAF rule sets.
New micro-release; comes with PHP 8.3 handler support and updated Comodo/Atomicorp WAF rule sets.
Per customer requests, the PHP 8.3 handler will be enabled first on staging servers.
Static Code Injection in Plesk extensions "Ruby" before 1.6.6 and "Node.js Toolkit" before 2.5.0 allows remote authenticated users to execute arbitrary code as root via custom environment variables.
Improper neutralization of special elements in Plesk allows remote authenticated users to disclose arbitrary local files and escalate privileges.
Improper symlink resolution before file access in Plesk allows remote authenticated users to execute arbitrary code as root.