CVE-2011-4765: Parallels Plesk Small Business Panel
Medium severity, CVSS 4.3. EPSS: 1% chance of exploitation in the next 30 days.
The Site Editor (aka SiteBuilder) feature in Parallels Plesk Small Business Panel 10.2.0 does not include the HTTPOnly flag in a Set-Cookie header for a cookie, which makes it easier for remote attackers to obtain potentially sensitive information via script access to this cookie, as demonstrated by cookies used by Wizard/Edit/Modules/ImageGallery/MultiImagesUpload and certain other files.
Affected products
- Parallels Parallels Plesk Small Business Panel: version 10.2.0 only
Published 2011-12-16. Last modified 2026-06-16.