Looking for the vulnerability index of Invicti's legacy products?
Parallels Plesk SSO XML External Entity and Cross-site scripting - Vulnerability Database

Parallels Plesk SSO XML External Entity and Cross-site scripting

Description

The Parallels Plesk Panel software package is a commercial web hosting automation program. Parallels Plesk Single Sign-On (SSO) technology make it easy for customers to use and manage applications, and reduce the administrative costs of password management for hosting providers. Parallels Plesk Single Sign-On (SSO) implementation was found vulnerable to XXE (XML External Entity) and XSS (Cross-site scripting) vulnerabilities.

Remediation

To disable SSO-mode in Parallels Plesk Panel: <br/> <pre> ~# /usr/local/psa/bin/sso --disable </pre>