CVE-2011-4749: Parallels Plesk Panel

High severity, CVSS 10.0. EPSS: 2.2% chance of exploitation in the next 30 days.

The billing system for Parallels Plesk Panel 10.3.1_build1013110726.09 generates a password form field without disabling the autocomplete feature, which makes it easier for remote attackers to bypass authentication by leveraging an unattended workstation, as demonstrated by forms on certain pages under admin/index.php/default.

Affected products

  • Parallels Parallels Plesk Panel: version 10.3.1_build1013110726.09 only

Published 2011-12-16. Last modified 2026-06-16.