LiveActive security incident?Get immediate response
CVE Record

CVE-2021-30071: A cross-site scripting (XSS) vulnerability in /admin/list_key.html of HestiaCP before v1.3.5 allows attacke...

A cross-site scripting (XSS) vulnerability in /admin/list_key.html of HestiaCP before v1.3.5 allows attackers to execute arbitrary web scripts or HTML via a crafted payload.

UnknownCVSS not scoredNot KEV-listedUpdated
Glexia's TakeAutomated analysismoderate

Security readout for executives and security teams

Plain-English summary

CVE-2021-30071 is a cross-site scripting issue in HestiaCP before v1.3.5. A crafted value could cause script or HTML to run in the browser when the vulnerable admin key list page is viewed. Business urgency depends on whether the HestiaCP admin interface is deployed and reachable.

Executive priority

Treat as a targeted administrative web-panel risk. Prioritize remediation if HestiaCP is internet-facing, externally administered, or used by multiple administrators. If HestiaCP is absent, no action is needed beyond inventory confirmation.

Technical view

The source describes XSS in /admin/list_key.html of HestiaCP before v1.3.5, with a GitHub commit referenced as the remediation evidence. The public record does not provide CVSS, CWE, exact injection mechanics, authentication requirements, or a complete affected CPE list.

Likely exposure

Exposure is most likely for organizations running HestiaCP before v1.3.5, especially where the admin interface is accessible to many users or from untrusted networks. The source bundle’s structured affected-product fields are incomplete.

Exploitation context

No provided source or KEV status supports active exploitation. The issue is described as requiring a crafted payload that results in arbitrary web script or HTML execution in the vulnerable admin page context.

Researcher notes

Evidence is sparse: the CVE record names the vulnerable path and pre-1.3.5 version boundary, but omits CVSS, CWE, exploit prerequisites, and affected CPEs. Avoid assuming stored versus reflected behavior without reviewing the referenced code change.

Mitigation direction

  • Upgrade HestiaCP to v1.3.5 or a later vendor-supported release.
  • Review the referenced HestiaCP commit and release guidance.
  • Restrict access to the HestiaCP admin interface to trusted networks and users.
  • Monitor administrator sessions for unusual activity around key-list management pages.

Validation and detection

  • Inventory all HestiaCP instances and record deployed versions.
  • Confirm no production instance is older than v1.3.5.
  • Verify /admin/list_key.html output is safely escaped in a controlled test environment.
  • Review admin access logs for suspicious requests to /admin/list_key.html.
Prepared
Confidence
medium
Sources
3

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Potential ATT&CK relevance

Conservative CVE-to-ATT&CK context

These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.

ATT&CK lookup starting points

Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.

cve · low confidence lookup

CVE-2021-30071 mapping review

Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.

Open ATT&CK lookup
Vulnerability profileCVE Program record
Severity
Unknown
CVSS
Not scored
Known Exploited
No
Published
Official CVE source material

CNA and ADP enrichment extracted from CVE v5

These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.

0CVSS vectors
0Timeline events
0ADP providers
2Source links

CVSS and timeline data

No CVSS vectors or timeline events were available in the normalized CVE source material.

Affected products

Products and packages named in the record

VendorProductVersion / packageStatus
n/an/an/aListed
Weakness

CWE details

No CWE listed

CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.