CVE-2024-39911

1Panel is a web-based linux server management control panel. 1Panel contains an unspecified sql injection via User-Agent handling. This issue has been addressed in version 1.10.12-lts. Users are advised to upgrade. There are no known workarounds for this vulnerability.
Configurations

Configuration 1 (hide)

cpe:2.3:a:fit2cloud:1panel:*:*:*:*:*:*:*:*

History

10 Sep 2024, 19:12

Type Values Removed Values Added
CPE cpe:2.3:a:fit2cloud:1panel:*:*:*:*:*:*:*:*
First Time Fit2cloud
Fit2cloud 1panel
CVSS v2 : unknown
v3 : 10.0
v2 : unknown
v3 : 9.8
References () https://blog.mo60.cn/index.php/archives/1Panel_SQLinjection2Rce.html - () https://blog.mo60.cn/index.php/archives/1Panel_SQLinjection2Rce.html - Exploit, Third Party Advisory
References () https://github.com/1Panel-dev/1Panel/security/advisories/GHSA-7m53-pwp6-v3f5 - () https://github.com/1Panel-dev/1Panel/security/advisories/GHSA-7m53-pwp6-v3f5 - Exploit, Vendor Advisory

19 Jul 2024, 13:01

Type Values Removed Values Added
Summary
  • (es) 1Panel es un panel de control de gestión de servidores Linux basado en web. 1Panel contiene una inyección de SQL no especificada mediante el manejo de User-Agent. Este problema se solucionó en la versión 1.10.12-lts. Se recomienda a los usuarios que actualicen. No se conocen workarounds para esta vulnerabilidad.

18 Jul 2024, 20:15

Type Values Removed Values Added
References
  • () https://blog.mo60.cn/index.php/archives/1Panel_SQLinjection2Rce.html -

18 Jul 2024, 16:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-07-18 16:15

Updated : 2024-09-10 19:12


NVD link : CVE-2024-39911

Mitre link : CVE-2024-39911

CVE.ORG link : CVE-2024-39911


JSON object : View

Products Affected

fit2cloud

  • 1panel
CWE
CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')