← Voltar para CVEs
CVE-2024-39907
CRITICAL9.8
Descricao
1Panel is a web-based linux server management control panel. There are many sql injections in the project, and some of them are not well filtered, leading to arbitrary file writes, and ultimately leading to RCEs. These sql injections have been resolved in version 1.10.12-tls. Users are advised to upgrade. There are no known workarounds for these issues.
Detalhes CVE
Pontuacao CVSS v3.19.8
SeveridadeCRITICAL
Vetor CVSSCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Vetor de ataqueNETWORK
ComplexidadeLOW
Privilegios necessariosNONE
Interacao do usuarioNONE
Publicado7/18/2024
Ultima modificacao11/21/2024
Fontenvd
Avistamentos honeypot0
Produtos afetados
fit2cloud:1panel
Fraquezas (CWE)
CWE-89CWE-89
Referencias
https://github.com/1Panel-dev/1Panel/security/advisories/GHSA-5grx-v727-qmq6(security-advisories@github.com)
https://github.com/1Panel-dev/1Panel/security/advisories/GHSA-5grx-v727-qmq6(af854a3a-2127-422b-91ae-364da2661108)
Correlacoes IOC
Sem correlacoes registradas
This product uses data from the NVD API but is not endorsed or certified by the NVD.