Remote Command Execution Vulnerability in Max Knowledge Base by 1Panel
CVE-2024-56137

6.8MEDIUM

Key Information:

Vendor
1panel-dev
Status
Maxkb
Vendor
CVE Published:
2 January 2025

Summary

MaxKB, an open source knowledge base question-answering system by 1Panel, has a vulnerability in its function library module that allows privileged users to execute operating system commands through custom scripts. This remote command execution flaw enables potential exploitation, where an attacker could run arbitrary commands with the privileges of the MaxKB application. The issue has been addressed in version 1.9.0, highlighting the importance for users to update their versions promptly to mitigate this risk. For more details and guidance, visit the official advisory.

Affected Version(s)

MaxKB < 1.9.0

References

CVSS V3.1

Score:
6.8
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.