CVE-2024-54679
- EPSS 0.92%
- Veröffentlicht 05.12.2024 14:15:22
- Zuletzt bearbeitet 05.09.2025 13:39:46
CyberPanel (aka Cyber Panel) before 6778ad1 does not require the FilemanagerAdmin capability for restartMySQL actions.
CVE-2024-51378
- EPSS 94.73%
- Veröffentlicht 29.10.2024 23:15:04
- Zuletzt bearbeitet 05.08.2026 05:16:41
getresetstatus in dns/views.py and ftp/views.py in CyberPanel (aka Cyber Panel) before 1c0c6cb allows remote attackers to bypass authentication and execute arbitrary commands via /dns/getresetstatus or /ftp/getresetstatus by bypassing secMiddleware (...
CVE-2024-51567
- EPSS 86.52%
- Veröffentlicht 29.10.2024 23:15:04
- Zuletzt bearbeitet 04.08.2026 05:16:31
upgrademysqlstatus in databases/views.py in CyberPanel (aka Cyber Panel) before 5b08cd6 allows remote attackers to bypass authentication and execute arbitrary commands via /dataBases/upgrademysqlstatus by bypassing secMiddleware (which is only for a ...
CVE-2024-51568
- EPSS 45.46%
- Veröffentlicht 29.10.2024 23:15:04
- Zuletzt bearbeitet 07.07.2025 16:17:23
CyberPanel (aka Cyber Panel) before 2.3.5 allows Command Injection via completePath in the ProcessUtilities.outputExecutioner() sink. There is /filemanager/upload (aka File Manager upload) unauthenticated remote code execution via shell metacharacter...
CVE-2019-13056
- EPSS 0.84%
- Veröffentlicht 02.07.2019 16:15:12
- Zuletzt bearbeitet 21.11.2024 04:24:07
An issue was discovered in CyberPanel through 1.8.4. On the user edit page, an attacker can edit the administrator's e-mail and password because of the lack of CSRF protection.