Home

Description

CyberPanel (aka Cyber Panel) before 2.3.5 allows Command Injection via completePath in the ProcessUtilities.outputExecutioner() sink. There is /filemanager/upload (aka File Manager upload) unauthenticated remote code execution via shell metacharacters.

PUBLISHED Reserved 2024-10-29 | Published 2024-10-29 | Updated 2024-10-30 | Assigner mitre




CRITICAL: 10.0CVSS:3.1/AC:L/AV:N/A:H/C:H/I:H/PR:N/S:C/UI:N

References

cwe.mitre.org/data/definitions/78.html

dreyand.rs/...at-are-my-options-cyberpanel-v236-pre-auth-rce

cyberpanel.net/KnowledgeBase/home/change-logs/

cyberpanel.net/blog/cyberpanel-v2-3-5

cve.org (CVE-2024-51568)

nvd.nist.gov (CVE-2024-51568)

Download JSON