vendor:
CyberPanel
by:
Luka Petrovic (refr4g)
6.1
CVSS
HIGH
Remote Code Execution (RCE)
78
CWE
Product Name: CyberPanel
Affected Version From: 2.3.2005
Affected Version To: 2.3.2007
Patch Exists: NO
Related CWE: CVE-2024-51378
CPE: a:cyberpanel:cyberpanel:2.3.6
Platforms Tested: Ubuntu 20.04
2024
CyberPanel 2.3.6 – Remote Code Execution (RCE)
The CyberPanel version 2.3.6 and earlier allows remote attackers to execute arbitrary code via a crafted request to specific endpoints, leading to command injection. This vulnerability has been assigned CVE-2024-51378.
Mitigation:
Update to version 2.3.8 or later to mitigate this vulnerability. Avoid exposing the CyberPanel interface to untrusted networks.