CVE-2015-4117: Vestacp Control Panel

High severity, CVSS 8.8. EPSS: 10.6% chance of exploitation in the next 30 days.

Vesta Control Panel before 0.9.8-14 allows remote authenticated users to execute arbitrary commands via shell metacharacters in the backup parameter to list/backup/index.php.

Affected products

  • Vestacp Control Panel: before 0.9.8-14 (fixed in 0.9.8-14)

Published 2018-02-28. Last modified 2026-06-17.