CVE-2023-24044: Plesk Obsidian

Medium severity, CVSS 6.1. EPSS: 2.3% chance of exploitation in the next 30 days.

A Host Header Injection issue on the Login page of Plesk Obsidian through 18.0.49 allows attackers to redirect users to malicious websites via a Host request header. NOTE: the vendor's position is "the ability to use arbitrary domain names to access the panel is an intended feature."

Affected products

  • Plesk Obsidian: up to and including 18.0.49

Published 2023-01-22. Last modified 2026-06-17.