Zpanel Project

Zpanel

3 vulnerabilities found.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.03%
  • Published 04.08.2025 18:03:58
  • Last modified 05.08.2025 16:15:27

ZPanel includes a helper binary named zsudo, intended to allow restricted privilege escalation for administrative tasks. However, when misconfigured in /etc/sudoers, zsudo can be invoked by low-privileged users to execute arbitrary commands as root. ...

Exploit
  • EPSS 0.65%
  • Published 01.08.2025 20:49:05
  • Last modified 04.08.2025 16:15:31

A remote command execution vulnerability exists in ZPanel version 10.0.0.2 in its htpasswd module. When creating .htaccess files, the inHTUsername field is passed unsanitized to a system() call that invokes the system’s htpasswd binary. By injecting ...

Exploit
  • EPSS 57.44%
  • Published 12.02.2020 16:15:10
  • Last modified 21.11.2024 01:51:01

ZPanel through 10.1.0 has Remote Command Execution