CSRF Vulnerability in 1Panel Affects User Account Security
CVE-2025-34410
What is CVE-2025-34410?
1Panel versions 1.10.33 to 2.0.15 are susceptible to a Cross-Site Request Forgery (CSRF) vulnerability in the Change Username functionality accessible through the settings panel. Due to insufficient CSRF protections, such as anti-CSRF tokens or proper Origin/Referer validation, an attacker can create a malicious website that, when visited by an authenticated user, prompts a hidden request to change their username. This can result in the unauthorized alteration of the victim's 1Panel username, causing account lockout and potential denial of service as the victim would be unable to access their account afterward.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
1Panel 1.10.33 <= 2.0.15
References
CVSS V4
Timeline
Vulnerability published
Vulnerability Reserved
