CVE-2024-39907
There are many sql injections in the project, and some of them are not well filtered, leading to arbitrary file writes, and ultimately leading to RCEs.
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 29.2%, higher than 98% of all known CVEs. Patch or mitigate before the next change window.
Description
1Panel is a web-based linux server management control panel. There are many sql injections in the project, and some of them are not well filtered, leading to arbitrary file writes, and ultimately leading to RCEs. These sql injections have been resolved in version 1.10.12-tls. Users are advised to upgrade. There are no known workarounds for these issues.
- CVSS 3.1
- 9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 29.18% probability · 98th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-89
- Affected
- fit2cloud/1panel
- Source
- security-advisories@github.com
References
- https://github.com/1Panel-dev/1Panel/security/advisories/GHSA-5grx-v727-qmq6Exploit, Third Party Advisory
- https://github.com/1Panel-dev/1Panel/security/advisories/GHSA-5grx-v727-qmq6Exploit, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.