Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-19875 | In Plesk Obsidian 18.0.69, unauthenticated requests to /login_up.php can reveal an AWS accessKeyId, secretAccessKey, region, and endpoint. |
Thu, 03 Jul 2025 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 03 Jul 2025 13:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-402 | |
| Metrics |
cvssV3_1
|
Thu, 03 Jul 2025 12:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | In Plesk Obsidian 18.0.69, unauthenticated requests to /login_up.php can reveal an AWS accessKeyId, secretAccessKey, region, and endpoint. | |
| References |
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2025-07-03T13:17:49.348Z
Reserved: 2025-06-07T00:00:00.000Z
Link: CVE-2025-49618
Updated: 2025-07-03T13:13:46.956Z
Status : Deferred
Published: 2025-07-03T13:15:28.860
Modified: 2026-04-15T00:35:42.020
Link: CVE-2025-49618
No data.
OpenCVE Enrichment
Updated: 2025-07-06T22:16:20Z
EUVD