CVE-2024-51568: Command Injection
CyberPanel (aka Cyber Panel) before 2.3.5 allows Command Injection via completePath in the ProcessUtilities.outputExecutioner() sink. There is /filemanager/upload (aka File Manager upload) unauthenticated remote code execution via shell metacharacters.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-51568?
CVE-2024-51568 is classified as a critical vulnerability due to its ability to allow unauthenticated remote code execution.
How do I fix CVE-2024-51568?
The best way to address CVE-2024-51568 is to update CyberPanel to version 2.3.5 or later, which contains the necessary security fixes.
What are the potential impacts of CVE-2024-51568 on my system?
The impact of CVE-2024-51568 includes potential unauthorized command execution and compromise of the server hosting CyberPanel.
Is CVE-2024-51568 exploitable without authentication?
Yes, CVE-2024-51568 is exploitable without authentication, making it particularly dangerous for exposed systems.
What versions of CyberPanel are affected by CVE-2024-51568?
CVE-2024-51568 affects all versions of CyberPanel prior to 2.3.5.