CVE-2013-4878: Parallels Plesk Panel

High severity, CVSS 7.5. EPSS: 31.1% chance of exploitation in the next 30 days.

The default configuration of Parallels Plesk Panel 9.0.x and 9.2.x on UNIX, and Small Business Panel 10.x on UNIX, has an improper ScriptAlias directive for phppath, which makes it easier for remote attackers to execute arbitrary code via a crafted request, a different vulnerability than CVE-2012-1823.

Affected products

  • Parallels Parallels Plesk Panel: version 9.0 only; version 9.2 only
  • Parallels Parallels Small Business Panel: version 10.0 only

Published 2013-07-18. Last modified 2026-06-16.