Description
CyberPanel (aka Cyber Panel) before 2.3.5 allows Command Injection via completePath in the ProcessUtilities.outputExecutioner() sink. There is /filemanager/upload (aka File Manager upload) unauthenticated remote code execution via shell metacharacters.
References
cwe.mitre.org/data/definitions/78.html
dreyand.rs/...at-are-my-options-cyberpanel-v236-pre-auth-rce
cyberpanel.net/KnowledgeBase/home/change-logs/
cyberpanel.net/blog/cyberpanel-v2-3-5