Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-q2hv-8prh-hr3r

Опубликовано: 30 окт. 2024
Источник: github
Github: Не прошло ревью
CVSS3: 10

Описание

CyberPanel (aka Cyber Panel) before 2.3.5 allows Command Injection via completePath in the ProcessUtilities.outputExecutioner() sink. There is /filemanager/upload (aka File Manager upload) unauthenticated remote code execution via shell metacharacters.

CyberPanel (aka Cyber Panel) before 2.3.5 allows Command Injection via completePath in the ProcessUtilities.outputExecutioner() sink. There is /filemanager/upload (aka File Manager upload) unauthenticated remote code execution via shell metacharacters.

EPSS

Процентиль: 100%
0.92473
Критический

10 Critical

CVSS3

Дефекты

CWE-78

Связанные уязвимости

CVSS3: 10
nvd
больше 1 года назад

CyberPanel (aka Cyber Panel) before 2.3.5 allows Command Injection via completePath in the ProcessUtilities.outputExecutioner() sink. There is /filemanager/upload (aka File Manager upload) unauthenticated remote code execution via shell metacharacters.

EPSS

Процентиль: 100%
0.92473
Критический

10 Critical

CVSS3

Дефекты

CWE-78