1Panel Security Update: SQL Injections and RCEs
CVE-2024-39907

9.8CRITICAL

Key Information:

Vendor
1panel-dev
Status
Vendor
CVE Published:
18 July 2024

Summary

1Panel, a web-based Linux server management control panel, is susceptible to multiple SQL injection vulnerabilities that have not been adequately filtered. These vulnerabilities can lead to arbitrary file writes and, in critical scenarios, may allow for remote code execution (RCE). The issues have been addressed in version 1.10.12-tls, and users are strongly encouraged to upgrade to this version as there are currently no workarounds available. Ensuring the latest version is implemented is crucial for maintaining the security of your server management activities.

Affected Version(s)

1Panel >= 1.10.9-tls, < 1.10.12-tls

References

EPSS Score

64% chance of being exploited in the next 30 days.

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.