Vulnerability when adding domains/subdomains
Posted: Tue Jun 06, 2023 6:14 pm
There is a problem or possible vulnerability that has been carried over from the main project "VestaCP".
When adding a subdomain, there is no verification that is in charge of verifying if the subdomain that the user wants to create is already in use by another user, for example, the panel domain (admin user) is: domain.com
Any other user can create subdomains using the main domain without problems, the same would happen with any other main domain of any user and that is a problem... Previously HestiaCP had the same problem two years ago but they took into consideration my report in the forum and in the next update they fixed it.
When adding a subdomain, there is no verification that is in charge of verifying if the subdomain that the user wants to create is already in use by another user, for example, the panel domain (admin user) is: domain.com
Any other user can create subdomains using the main domain without problems, the same would happen with any other main domain of any user and that is a problem... Previously HestiaCP had the same problem two years ago but they took into consideration my report in the forum and in the next update they fixed it.