1Panel Security Update: SQL Injections and RCEs
CVE-2024-39907
What is CVE-2024-39907?
1Panel, a web-based Linux server management control panel, is susceptible to multiple SQL injection vulnerabilities that have not been adequately filtered. These vulnerabilities can lead to arbitrary file writes and, in critical scenarios, may allow for remote code execution (RCE). The issues have been addressed in version 1.10.12-tls, and users are strongly encouraged to upgrade to this version as there are currently no workarounds available. Ensuring the latest version is implemented is crucial for maintaining the security of your server management activities.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
1Panel >= 1.10.9-tls, < 1.10.12-tls
References
EPSS Score
84% chance of being exploited in the next 30 days.
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved
