X-Forwarded-For Header Spoofing in 1Panel Web Control Panel
CVE-2025-66508
6.5MEDIUM
What is CVE-2025-66508?
1Panel, a web-based control panel designed for Linux server management, is susceptible to an IP address spoofing vulnerability due to the misuse of Gin's default configuration. This flaw allows attackers to exploit the X-Forwarded-For header manipulation, enabling them to falsify their IP address and bypass existing IP-based access controls. By sending forged X-Forwarded-For requests, attackers can exploit security measures relying on ClientIP, effectively undermining the integrity of API whitelists and access restrictions. The vulnerability has been addressed in version 2.0.14, emphasizing the importance of maintaining updated software to protect against such threats.
Affected Version(s)
1Panel < 2.0.14
