CVE-2020-10966: Hestiacp Control Panel
Medium severity, CVSS 6.5. EPSS: 1.9% chance of exploitation in the next 30 days.
In the Password Reset Module in VESTA Control Panel through 0.9.8-25 and Hestia Control Panel before 1.1.1, Host header manipulation leads to account takeover because the victim receives a reset URL containing an attacker-controlled server name.
Affected products
- Hestiacp Control Panel: before 1.1.1 (fixed in 1.1.1)
- Vestacp Control Panel: up to and including 0.9.8-25
Published 2020-03-25. Last modified 2026-06-17.