{"id":"CVE-2021-30462","details":"VestaCP through 0.9.8-24 allows the admin user to escalate privileges to root because the Sudo configuration does not require a password to run /usr/local/vesta/bin scripts.","modified":"2026-08-27T08:14:40.883616Z","published":"2021-04-08T14:15:14.213Z","references":[{"type":"EVIDENCE","url":"https://ssd-disclosure.com/ssd-advisory-vestacp-lpe-vulnerabilities/"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/outroll/vesta","events":[{"introduced":"0"},{"last_affected":"2da2c539f169c7c4a00b1e23fcf9c3c226faeb08"}],"database_specific":{"cpe":"cpe:2.3:a:vestacp:vesta_control_panel:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"0"},{"last_affected":"0.9.8-24"}],"source":"CPE_RANGE"}}],"versions":["0.9.8-24","0.9.8-23","0.9.8-20","0.9.8-19","0.9.8-18","0.9.8-17","0.9.8-16","0.9.8-15","0.9.8-13","0.9.8-12","0.9.8-11","0.9.8-10"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2021-30462.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H"}]}