CVE-2021-47949: CyberPanel 2.1 Authenticated Remote Code Execution via Symlink Attack
CyberPanel 2.1 contains a command execution vulnerability that allows authenticated attackers to read arbitrary files and execute remote code by exploiting symlink attacks through the filemanager controller endpoint. Attackers can manipulate the completeStartingPath parameter in POST requests to /filemanager/controller to create symbolic links, read sensitive files like database credentials, and execute arbitrary shell commands through the /websites/fetchFolderDetails endpoint.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2021-47949?
CVE-2021-47949 is considered a critical vulnerability due to its potential for authentication bypass and remote code execution.
How do I fix CVE-2021-47949?
To mitigate CVE-2021-47949, update CyberPanel to the latest version where the vulnerability is patched.
What type of attack is associated with CVE-2021-47949?
CVE-2021-47949 is associated with symlink attacks that allow for remote code execution.
Who is affected by CVE-2021-47949?
Users of CyberPanel version 2.1 are affected by CVE-2021-47949.
What are the potential consequences of CVE-2021-47949?
Exploitation of CVE-2021-47949 can lead to exposure of sensitive files and execution of arbitrary code on the server.