Логотип exploitDog
bind:CVE-2025-66507
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2025-66507

Количество 2

Количество 2

nvd логотип

CVE-2025-66507

2 месяца назад

1Panel is an open-source, web-based control panel for Linux server management. Versions 2.0.13 and below allow an unauthenticated attacker to disable CAPTCHA verification by abusing a client-controlled parameter. Because the server previously trusted this value without proper validation, CAPTCHA protections can be bypassed, enabling automated login attempts and significantly increasing the risk of account takeover (ATO). This issue is fixed in version 2.0.14.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-qmg5-v42x-qqhq

2 месяца назад

1Panel – CAPTCHA Bypass via Client-Controlled Flag

CVSS3: 7.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2025-66507

1Panel is an open-source, web-based control panel for Linux server management. Versions 2.0.13 and below allow an unauthenticated attacker to disable CAPTCHA verification by abusing a client-controlled parameter. Because the server previously trusted this value without proper validation, CAPTCHA protections can be bypassed, enabling automated login attempts and significantly increasing the risk of account takeover (ATO). This issue is fixed in version 2.0.14.

CVSS3: 7.5
0%
Низкий
2 месяца назад
github логотип
GHSA-qmg5-v42x-qqhq

1Panel – CAPTCHA Bypass via Client-Controlled Flag

CVSS3: 7.5
0%
Низкий
2 месяца назад

Уязвимостей на страницу