CVE-2025-49618 Information
Jul 04, 2025
cve
Description
In Plesk Obsidian 18.0.69 unauthenticated requests to /login_up.php can reveal an AWS accessKeyId secretAccessKey region and endpoint.
Reference
https://www.linkedin.com/posts/gaetano-cesano-976420200_qualche-giorno-fa-stavo-testando-plesk-obsidian-activity-7341794923198709761-by9G https://www.plesk.com/blog/plesk-news-announcements/plesk-obsidian-18-0-69-is-here/
Related CNNVD
CNNVD-202507-291 (Published: 2025-07-03)
Share on: