Unauthorized Remote Code Execution via Shell Metacharacters in File Manager Upload
CVE-2024-51568
Key Information:
- Vendor
CyberPanel
- Status
- Vendor
- CVE Published:
- 29 October 2024
Badges
What is CVE-2024-51568?
A vulnerability in CyberPanel prior to version 2.3.5 allows attackers to execute commands on the server through the ProcessUtilities.outputExecutioner() function. This command injection can be exploited via the file manager upload feature, where unauthenticated users may leverage shell metacharacters to execute arbitrary code. The lack of proper validation makes this a serious threat to the security of systems utilizing CyberPanel, enabling potential unauthorized access and control.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
News Articles
References
EPSS Score
92% chance of being exploited in the next 30 days.
CVSS V3.1
Timeline
- đź“°
First article discovered by TheCyberThrone
Vulnerability published
