1Panel Security Update: SQL Injections and RCEs
CVE-2024-39907
9.8CRITICAL
Summary
1Panel, a web-based Linux server management control panel, is susceptible to multiple SQL injection vulnerabilities that have not been adequately filtered. These vulnerabilities can lead to arbitrary file writes and, in critical scenarios, may allow for remote code execution (RCE). The issues have been addressed in version 1.10.12-tls, and users are strongly encouraged to upgrade to this version as there are currently no workarounds available. Ensuring the latest version is implemented is crucial for maintaining the security of your server management activities.
Affected Version(s)
1Panel >= 1.10.9-tls, < 1.10.12-tls
References
EPSS Score
64% chance of being exploited in the next 30 days.
CVSS V3.1
Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved