Remote Command Execution Vulnerability in Max Knowledge Base by 1Panel
CVE-2024-56137
6.8MEDIUM
Key Information:
- Vendor
- 1panel-dev
- Status
- Maxkb
- Vendor
- CVE Published:
- 2 January 2025
Summary
MaxKB, an open source knowledge base question-answering system by 1Panel, has a vulnerability in its function library module that allows privileged users to execute operating system commands through custom scripts. This remote command execution flaw enables potential exploitation, where an attacker could run arbitrary commands with the privileges of the MaxKB application. The issue has been addressed in version 1.9.0, highlighting the importance for users to update their versions promptly to mitigate this risk. For more details and guidance, visit the official advisory.
Affected Version(s)
MaxKB < 1.9.0
References
CVSS V3.1
Score:
6.8
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved