Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Thu, 05 Mar 2026 02:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:hestiacp:control_panel:1.3.3:*:*:*:*:*:*:* |
Fri, 23 Jan 2026 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Hestiacp
Hestiacp control Panel |
|
| Vendors & Products |
Hestiacp
Hestiacp control Panel |
Thu, 22 Jan 2026 23:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 21 Jan 2026 17:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Hestia Control Panel 1.3.2 contains an arbitrary file write vulnerability that allows authenticated attackers to write files to arbitrary locations using the API index.php endpoint. Attackers can exploit the v-make-tmp-file command to write SSH keys or other content to specific file paths on the server. | |
| Title | Hestia Control Panel 1.3.2 - Arbitrary File Write | |
| Weaknesses | CWE-73 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-03-05T01:29:02.458Z
Reserved: 2026-01-18T12:35:05.171Z
Link: CVE-2021-47871
Updated: 2026-01-22T16:47:07.128Z
Status : Deferred
Published: 2026-01-21T18:16:20.190
Modified: 2026-04-15T00:35:42.020
Link: CVE-2021-47871
No data.
OpenCVE Enrichment
Updated: 2026-01-22T10:08:51Z