Cross-Site WebSocket Hijacking Vulnerability in aaPanel by aaPanel
CVE-2021-37840
8.8HIGH
What is CVE-2021-37840?
The vulnerability in aaPanel versions up to 6.8.12 allows for Cross-Site WebSocket Hijacking, enabling potential attackers to conduct OS command injection through manipulated WebSocket messages sent to vulnerable servers. This attack method requires the target to have WebSSH set up and at least one host configured. Exploitation techniques can vary based on the browser types, potentially succeeding on systems like Firefox. Users should take immediate steps to secure their configurations against such exploits.
