Remote Command Execution Vulnerability in Max Knowledge Base by 1Panel
CVE-2024-56137

7.2HIGH

Key Information:

Vendor

1panel-dev

Status
Vendor
CVE Published:
2 January 2025

What is CVE-2024-56137?

MaxKB, an open source knowledge base question-answering system by 1Panel, has a vulnerability in its function library module that allows privileged users to execute operating system commands through custom scripts. This remote command execution flaw enables potential exploitation, where an attacker could run arbitrary commands with the privileges of the MaxKB application. The issue has been addressed in version 1.9.0, highlighting the importance for users to update their versions promptly to mitigate this risk. For more details and guidance, visit the official advisory.

Affected Version(s)

MaxKB < 1.9.0

References

CVSS V3.1

Score:
7.2
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.