Security readout for executives and security teams
Plain-English summary
CVE-2021-30071 is a cross-site scripting issue in HestiaCP before v1.3.5. A crafted value could cause script or HTML to run in the browser when the vulnerable admin key list page is viewed. Business urgency depends on whether the HestiaCP admin interface is deployed and reachable.
Executive priority
Treat as a targeted administrative web-panel risk. Prioritize remediation if HestiaCP is internet-facing, externally administered, or used by multiple administrators. If HestiaCP is absent, no action is needed beyond inventory confirmation.
Technical view
The source describes XSS in /admin/list_key.html of HestiaCP before v1.3.5, with a GitHub commit referenced as the remediation evidence. The public record does not provide CVSS, CWE, exact injection mechanics, authentication requirements, or a complete affected CPE list.
Likely exposure
Exposure is most likely for organizations running HestiaCP before v1.3.5, especially where the admin interface is accessible to many users or from untrusted networks. The source bundle’s structured affected-product fields are incomplete.
Exploitation context
No provided source or KEV status supports active exploitation. The issue is described as requiring a crafted payload that results in arbitrary web script or HTML execution in the vulnerable admin page context.
Researcher notes
Evidence is sparse: the CVE record names the vulnerable path and pre-1.3.5 version boundary, but omits CVSS, CWE, exploit prerequisites, and affected CPEs. Avoid assuming stored versus reflected behavior without reviewing the referenced code change.
Mitigation direction
- Upgrade HestiaCP to v1.3.5 or a later vendor-supported release.
- Review the referenced HestiaCP commit and release guidance.
- Restrict access to the HestiaCP admin interface to trusted networks and users.
- Monitor administrator sessions for unusual activity around key-list management pages.
Validation and detection
- Inventory all HestiaCP instances and record deployed versions.
- Confirm no production instance is older than v1.3.5.
- Verify /admin/list_key.html output is safely escaped in a controlled test environment.
- Review admin access logs for suspicious requests to /admin/list_key.html.
Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.
Conservative CVE-to-ATT&CK context
These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.
ATT&CK lookup starting points
Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.
CVE-2021-30071 mapping review
Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.
Open ATT&CK lookup- Severity
- Unknown
- CVSS
- Not scored
- Known Exploited
- No
- Published
CNA and ADP enrichment extracted from CVE v5
These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.
CVSS and timeline data
No CVSS vectors or timeline events were available in the normalized CVE source material.
Source materials
- CVE List V5 sourceCVE List V5
- https://github.com/hestiacp/hestiacp/commit/706314c12872c7607e96a73dfc77dbbddad2875eCVE reference · x_refsource_MISC
Products and packages named in the record
CWE details
CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.
