CloudPanel 2 before 2.3.1 has insecure file-manager cookie authentication.
References
Link | Resource |
---|---|
https://github.com/datackmy/FallingSkies-CVE-2023-35885 | Exploit |
https://www.cloudpanel.io/docs/v2/changelog/ | Release Notes |
https://www.datack.my/fallingskies-cloudpanel-0-day/ | Exploit |
https://github.com/datackmy/FallingSkies-CVE-2023-35885 | Exploit |
https://www.cloudpanel.io/docs/v2/changelog/ | Release Notes |
https://www.datack.my/fallingskies-cloudpanel-0-day/ | Exploit |
Configurations
History
21 Nov 2024, 08:08
Type | Values Removed | Values Added |
---|---|---|
References | () https://github.com/datackmy/FallingSkies-CVE-2023-35885 - Exploit | |
References | () https://www.cloudpanel.io/docs/v2/changelog/ - Release Notes | |
References | () https://www.datack.my/fallingskies-cloudpanel-0-day/ - Exploit |
02 Aug 2023, 16:42
Type | Values Removed | Values Added |
---|---|---|
References | (MISC) https://github.com/datackmy/FallingSkies-CVE-2023-35885 - Exploit | |
References | (MISC) https://www.datack.my/fallingskies-cloudpanel-0-day/ - Exploit |
20 Jul 2023, 19:15
Type | Values Removed | Values Added |
---|---|---|
References |
|
28 Jun 2023, 02:06
Type | Values Removed | Values Added |
---|---|---|
CPE | cpe:2.3:a:mgt-commerce:cloudpanel:*:*:*:*:*:*:*:* | |
References | (MISC) https://www.cloudpanel.io/docs/v2/changelog/ - Release Notes | |
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 9.8 |
First Time |
Mgt-commerce cloudpanel
Mgt-commerce |
|
CWE | CWE-565 |
20 Jun 2023, 20:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2023-06-20 20:15
Updated : 2024-11-21 08:08
NVD link : CVE-2023-35885
Mitre link : CVE-2023-35885
CVE.ORG link : CVE-2023-35885
JSON object : View
Products Affected
mgt-commerce
- cloudpanel
CWE
CWE-565
Reliance on Cookies without Validation and Integrity Checking