跳转到帖子

CyberPanel Multi CVE Pre-auth RCE

recommended_posts

发布于
  • Members

CyberPanel Multi CVE Pre-auth RCE

Disclosed
10/27/2024
Created
12/05/2024

Description

This module exploits three separate unauthenticated Remote Code Execution vulnerabilities in CyberPanel: - CVE-2024-51567: Command injection vulnerability in the "upgrademysqlstatus" endpoint. - CVE-2024-51568: Command Injection via the "completePath" parameter in the "outputExecutioner" sink. - CVE-2024-51378: Unauthenticated RCE in "/ftp/getresetstatus" and "/dns/getresetstatus". These vulnerabilities were exploited in ransomware campaigns affecting over 22,000 CyberPanel instances, with the PSAUX ransomware being the primary actor in these attacks.

Author(s)

  • DreyAnd
  • Valentin Lobstein
  • Luka Petrovic (refr4g)

Platform

Linux,Unix

Architectures

cmd

Development

  • Source Code
  • History
  • 查看数 695
  • 已创建
  • 最后回复

参与讨论

你可立刻发布并稍后注册。 如果你有帐户,立刻登录发布帖子。

游客
回帖…