CVE-2025-65518

7.5

Plesk · Obsidian

Plesk Obsidian versions 8.0.1 through 18.0.73 are vulnerable to a remote, unauthenticated Denial of Service via the get_password.php endpoint.

Executive summary

Plesk Obsidian versions 8.0.1 through 18.0.73 are susceptible to an unauthenticated Denial of Service attack, which could render the administrative interface unreachable.

Vulnerability

The vulnerability exists in the get_password.php endpoint, where an unauthenticated remote attacker can submit a crafted payload to force the interface into a continuous reload loop. This flaw results in a complete loss of service availability for the affected instance.

Business impact

Successful exploitation results in a Denial of Service, which effectively takes the Plesk management interface offline for all users. Given the CVSS score of 7.5, this high severity vulnerability poses a significant risk to operational continuity, potentially preventing administrators from managing server configurations or security settings during an outage.

Remediation

Immediate Action: Review the official Plesk change logs and apply the latest security updates provided by the vendor to resolve the vulnerability.

Proactive Monitoring: Monitor server access logs for repeated, suspicious requests targeting the get_password.php endpoint that correlate with service performance degradation.

Compensating Controls: Implement Web Application Firewall (WAF) rules to filter or block requests containing malicious payloads targeting the vulnerable endpoint until a patch can be applied.

Exploitation status

Public Exploit Available: Yes, a public proof-of-concept exists as documented in a GitHub repository linked in the reference data.

Analyst recommendation

This vulnerability represents a significant availability risk to Plesk Obsidian environments. Administrators must prioritize updating their installations as soon as the vendor releases the corresponding security patch to ensure service stability and prevent potential disruption from unauthenticated actors.

More Plesk CVEs

Sources