Cross-Site WebSocket Hijacking Vulnerability in aaPanel by aaPanel
CVE-2021-37840
8.8HIGH
What is CVE-2021-37840?
The vulnerability in aaPanel versions up to 6.8.12 allows for Cross-Site WebSocket Hijacking, enabling potential attackers to conduct OS command injection through manipulated WebSocket messages sent to vulnerable servers. This attack method requires the target to have WebSSH set up and at least one host configured. Exploitation techniques can vary based on the browser types, potentially succeeding on systems like Firefox. Users should take immediate steps to secure their configurations against such exploits.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
References
CVSS V3.1
Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
