CyberPanel (aka Cyber Panel) before 2.3.5 allows Command Injection via completePath in the ProcessUtilities.outputExecutioner() sink. There is /filemanager/upload (aka File Manager upload) unauthenticated remote code execution via shell metacharacters.
Metrics
Affected Vendors & Products
References
History
Wed, 30 Oct 2024 14:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Cyber Panel
Cyber Panel cyber Panel |
|
Weaknesses | CWE-78 | |
CPEs | cpe:2.3:a:cyber_panel:cyber_panel:*:*:*:*:*:*:*:* | |
Vendors & Products |
Cyber Panel
Cyber Panel cyber Panel |
|
Metrics |
ssvc
|
Tue, 29 Oct 2024 23:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | CyberPanel (aka Cyber Panel) before 2.3.5 allows Command Injection via completePath in the ProcessUtilities.outputExecutioner() sink. There is /filemanager/upload (aka File Manager upload) unauthenticated remote code execution via shell metacharacters. | |
References |
| |
Metrics |
cvssV3_1
|
MITRE
Status: PUBLISHED
Assigner: mitre
Published: 2024-10-29T00:00:00
Updated: 2024-10-30T13:44:45.134Z
Reserved: 2024-10-29T00:00:00
Link: CVE-2024-51568
Vulnrichment
Updated: 2024-10-30T13:44:39.152Z
NVD
Status : Awaiting Analysis
Published: 2024-10-29T23:15:04.520
Modified: 2024-11-01T12:57:03.417
Link: CVE-2024-51568
Redhat
No data.