1Panel Linux Server Management Control Panel User-Agent Handling Vulnerability
CVE-2024-39911

10CRITICAL

Key Information:

Vendor
1panel-dev
Status
Vendor
CVE Published:
18 July 2024

Summary

1Panel, a web-based Linux server management control panel, is susceptible to a SQL injection attack due to improper handling of User-Agent data. This vulnerability allows attackers to exploit the system by executing arbitrary SQL queries, potentially compromising the integrity and confidentiality of the system. The issue has been rectified in version 1.10.12-lts, and it is crucial for users to upgrade to this version as there are no available workarounds to mitigate the risks associated with this vulnerability.

Affected Version(s)

1Panel < 1.10.12-lts

References

EPSS Score

36% chance of being exploited in the next 30 days.

CVSS V3.1

Score:
10
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.