CyberRota Analysis
AI-GeneratedPlesk extensions "Ruby" prior to version 1.6.6 and "Node.js Toolkit" prior to version 2.5.0 are vulnerable to static code injection, enabling remote authenticated users to execute arbitrary code with root privileges through custom environment variables. This high-severity vulnerability poses a significant risk to systems utilizing these extensions, particularly in environments where user authentication is not adequately controlled. Administrators of affected Plesk installations should prioritize immediate updates to mitigate potential exploitation.
Original NVD Description
Static Code Injection in Plesk extensions "Ruby" before 1.6.6 and "Node.js Toolkit" before 2.5.0 allows remote authenticated users to execute arbitrary code as root via custom environment variables.