Fit2cloud

1panel

20 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.14%
  • Veröffentlicht 18.04.2024 15:15:30
  • Zuletzt bearbeitet 11.02.2025 17:46:01

1Panel is an open source Linux server operation and maintenance management panel. The password verification in the source code uses the != symbol instead hmac.Equal. This may lead to a timing attack vulnerability. This vulnerability is fixed in 1.10....

Exploit
  • EPSS 1.48%
  • Veröffentlicht 10.03.2024 02:16:08
  • Zuletzt bearbeitet 05.02.2025 13:55:32

A vulnerability, which was classified as critical, has been found in 1Panel up to 1.10.1-lts. Affected by this issue is the function baseApi.UpdateDeviceSwap of the file /api/v1/toolbox/device/update/swap. The manipulation of the argument Path with t...

Exploit
  • EPSS 0.45%
  • Veröffentlicht 06.03.2024 19:15:07
  • Zuletzt bearbeitet 11.02.2025 17:51:17

1Panel is an open source Linux server operation and maintenance management panel. Prior to version 1.10.1-lts, users can use Burp to obtain unauthorized access to the console page. The vulnerability has been fixed in v1.10.1-lts. There are no known w...

  • EPSS 0.06%
  • Veröffentlicht 05.02.2024 15:15:09
  • Zuletzt bearbeitet 21.11.2024 08:59:39

1Panel is an open source Linux server operation and maintenance management panel. The HTTPS cookie that comes with the panel does not have the Secure keyword, which may cause the cookie to be sent in plain text if accessed using HTTP. This issue has ...

Exploit
  • EPSS 0.19%
  • Veröffentlicht 10.08.2023 18:15:11
  • Zuletzt bearbeitet 21.11.2024 08:16:08

1Panel is an open source Linux server operation and maintenance management panel. In version 1.4.3, an arbitrary file write vulnerability could lead to direct control of the server. In the `api/v1/file.go` file, there is a function called `SaveConten...

Exploit
  • EPSS 0.09%
  • Veröffentlicht 10.08.2023 18:15:11
  • Zuletzt bearbeitet 21.11.2024 08:16:08

1Panel is an open source Linux server operation and maintenance management panel. In version 1.4.3, authenticated attackers can download arbitrary files through the API interface. This code has unauthorized access. Attackers can freely download the f...

Exploit
  • EPSS 0.24%
  • Veröffentlicht 10.08.2023 18:15:11
  • Zuletzt bearbeitet 21.11.2024 08:16:08

1Panel is an open source Linux server operation and maintenance management panel. In version 1.4.3, arbitrary file reads allow an attacker to read arbitrary important configuration files on the server. In the `api/v1/file.go` file, there is a functio...

Exploit
  • EPSS 0.63%
  • Veröffentlicht 18.07.2023 19:15:09
  • Zuletzt bearbeitet 21.11.2024 08:11:47

1Panel is an open source Linux server operation and maintenance management panel. An OS command injection vulnerability exists in 1Panel firewall functionality. A specially-crafted HTTP request can lead to arbitrary command execution. An attacker can...

Exploit
  • EPSS 2.63%
  • Veröffentlicht 05.07.2023 21:15:09
  • Zuletzt bearbeitet 21.11.2024 08:09:45

1Panel is an open source Linux server operation and maintenance management panel. Prior to version 1.3.6, an authenticated attacker can craft a malicious payload to achieve command injection when adding container repositories. The vulnerability has b...

Exploit
  • EPSS 2.63%
  • Veröffentlicht 05.07.2023 21:15:09
  • Zuletzt bearbeitet 21.11.2024 08:09:45

1Panel is an open source Linux server operation and maintenance management panel. Prior to version 1.3.6, an authenticated attacker can craft a malicious payloads to achieve command injection when entering the container terminal. The vulnerability ha...