CVE-2020-14421: Critical severity mengnai aapanel host system vulnerability
aaPanel through 6.6.6 allows remote authenticated users to execute arbitrary commands via the Script Content box on the Add Cron Job screen.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for aaPanel through 6.6.6?
The vulnerability ID for aaPanel through 6.6.6 is CVE-2020-14421.
What is the severity of the vulnerability?
The severity of the vulnerability is critical with a CVSS score of 7.2.
What does the aaPanel vulnerability allow remote authenticated users to do?
The aaPanel vulnerability allows remote authenticated users to execute arbitrary commands via the Script Content box on the Add Cron Job screen.
Which software version is affected by the vulnerability?
The vulnerability affects aaPanel version 6.6.6.
Are there any references available for further information?
Yes, you can find more information about the aaPanel vulnerability at the following references: 1. [Packet Storm Security](http://packetstormsecurity.com/files/159575/aaPanel-6.6.6-Privilege-Escalation.html) 2. [aaPanel Forum](https://forum.aapanel.com) 3. [aaPanel GitHub](https://github.com/jenaye/aapanel)