Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-mmcx-mj26-p5c9

Опубликовано: 10 сент. 2026
Источник: github
Github: Не прошло ревью
CVSS4: 8.6
CVSS3: 7.2

Описание

CyberPanel before 3.0.5 fails to enforce two-factor authentication on API endpoints, allowing attackers to bypass TOTP requirements using password-derived tokens. Attackers who obtain an administrator's password can derive API tokens and perform administrative operations or create authenticated sessions without the second factor.

CyberPanel before 3.0.5 fails to enforce two-factor authentication on API endpoints, allowing attackers to bypass TOTP requirements using password-derived tokens. Attackers who obtain an administrator's password can derive API tokens and perform administrative operations or create authenticated sessions without the second factor.

EPSS

Процентиль: 37%
0.00435
Низкий

8.6 High

CVSS4

7.2 High

CVSS3

Дефекты

CWE-287

Связанные уязвимости

CVSS3: 7.2
nvd
13 дней назад

CyberPanel before 3.0.5 fails to enforce two-factor authentication on API endpoints, allowing attackers to bypass TOTP requirements using password-derived tokens. Attackers who obtain an administrator's password can derive API tokens and perform administrative operations or create authenticated sessions without the second factor.

EPSS

Процентиль: 37%
0.00435
Низкий

8.6 High

CVSS4

7.2 High

CVSS3

Дефекты

CWE-287