CVE-2024-39911: 1Panel SQL injection
1Panel is a web-based linux server management control panel. 1Panel contains an unspecified sql injection via User-Agent handling. This issue has been addressed in version 1.10.12-lts. Users are advised to upgrade. There are no known workarounds for this vulnerability.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-39911?
CVE-2024-39911 is a critical vulnerability due to potential SQL injection that could allow attackers to manipulate the database.
How do I fix CVE-2024-39911?
To fix CVE-2024-39911, users should upgrade to version 1.10.12-lts or later of 1Panel.
What versions of 1Panel are affected by CVE-2024-39911?
CVE-2024-39911 affects 1Panel versions prior to 1.10.12-lts, specifically those from version 1.10.10-lts and earlier.
Are there any known workarounds for CVE-2024-39911?
There are no known workarounds for CVE-2024-39911, and upgrading is the only mitigation.
What type of vulnerability is CVE-2024-39911?
CVE-2024-39911 is classified as an SQL injection vulnerability via User-Agent handling in 1Panel.