vendor:
Ajenti
by:
Jeremy Brown
7.5
CVSS
HIGH
Remote Code Execution
78
CWE
Product Name: Ajenti
Affected Version From: 2.1.31
Affected Version To: 2.1.31
Patch Exists: YES
Related CWE: N/A
CPE: a:ajenti:ajenti:2.1.31
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Ubuntu Linux
2019
Ajenti 2.1.31 – Remote Code Execution
Ajenti is a web control panel written in Python and AngularJS. One can locally monitor executed commands on the server while testing. Modified the JSON request username value to be `id` which allows for remote code execution. Tested Ajenti 2.1.31 on Ubuntu 18.04, fixed in 2.1.32.
Mitigation:
Upgrade to Ajenti 2.1.32 or later.