First published: Thu Jul 18 2024(Updated: )
1Panel is a web-based linux server management control panel. 1Panel contains an unspecified sql injection via User-Agent handling. This issue has been addressed in version 1.10.12-lts. Users are advised to upgrade. There are no known workarounds for this vulnerability.
Credit: security-advisories@github.com
Affected Software | Affected Version | How to fix |
---|---|---|
1Panel | >=1.10.10-lts<1.10.12-lts |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-39911 is a critical vulnerability due to potential SQL injection that could allow attackers to manipulate the database.
To fix CVE-2024-39911, users should upgrade to version 1.10.12-lts or later of 1Panel.
CVE-2024-39911 affects 1Panel versions prior to 1.10.12-lts, specifically those from version 1.10.10-lts and earlier.
There are no known workarounds for CVE-2024-39911, and upgrading is the only mitigation.
CVE-2024-39911 is classified as an SQL injection vulnerability via User-Agent handling in 1Panel.