Vulnerabilities > Cyberpanel

DATE CVE VULNERABILITY TITLE RISK
2024-10-29 CVE-2024-51378 OS Command Injection vulnerability in Cyberpanel
getresetstatus in dns/views.py and ftp/views.py in CyberPanel (aka Cyber Panel) before 1c0c6cb allows remote attackers to bypass authentication and execute arbitrary commands via /dns/getresetstatus or /ftp/getresetstatus by bypassing secMiddleware (which is only for a POST request) and using shell metacharacters in the statusfile property, as exploited in the wild in October 2024 by PSAUX.
network
low complexity
cyberpanel CWE-78
critical
9.8
2024-10-29 CVE-2024-51567 Missing Authentication for Critical Function vulnerability in Cyberpanel
upgrademysqlstatus in databases/views.py in CyberPanel (aka Cyber Panel) before 5b08cd6 allows remote attackers to bypass authentication and execute arbitrary commands via /dataBases/upgrademysqlstatus by bypassing secMiddleware (which is only for a POST request) and using shell metacharacters in the statusfile property, as exploited in the wild in October 2024 by PSAUX.
network
low complexity
cyberpanel CWE-306
critical
9.8
2019-07-02 CVE-2019-13056 Cross-Site Request Forgery (CSRF) vulnerability in Cyberpanel
An issue was discovered in CyberPanel through 1.8.4.
network
low complexity
cyberpanel CWE-352
8.8