HestiaCP < 1.9.5 Stored XSS via DNS Record Management Interface
Vulnerability Description
HestiaCP before 1.9.5 contains a stored cross-site scripting vulnerability that allows authenticated low-privilege users to inject arbitrary HTML by creating a DNS record with a double-quote followed by a script payload in the value field. The application fails to apply htmlspecialchars() encoding to the DNS record value field rendered into the data-sort-value HTML attribute in list_dns_rec.php, allowing the payload to execute in the browser of any user who views the DNS record list, including administrators.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-30008
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- Djibril Mounkoro
References
More from hestiacp
View All →Affected Vendor
hestiacp
View all reports →