Remote Command Execution Vulnerability in aaPanel Software
CVE-2020-14950
8.8HIGH
What is CVE-2020-14950?
A security vulnerability in aaPanel, prior to version 6.6.6, enables remote authenticated users to execute arbitrary commands on the server by manipulating shell metacharacters in a specific request to the Software Store settings. This flaw could potentially be exploited to disrupt services by controlling service operations such as start, stop, or restart, leading to unauthorized actions within the application.
