cbcvebase.
CVE-2024-34352
published 2024-05-14

CVE-2024-34352: 1Panel is an open source Linux server operation and maintenance management panel. Prior to v1.10.3-lts, there are many command injections in the project, and…

PriorityP347high7.5CVSS 3.1
AVNACLPRNUINSUCNIHAN
EPSS
1.33%
67.5th percentile
1Panel is an open source Linux server operation and maintenance management panel. Prior to v1.10.3-lts, there are many command injections in the project, and some of them are not well filtered, leading to arbitrary file writes, and ultimately leading to RCEs. The mirror configuration write symbol `>` can be used to achieve arbitrary file writing. This vulnerability is fixed in v1.10.3-lts.

Affected

3 ranges
VendorProductVersion rangeFixed in
1panel-dev1panel<= v1.10.2-lts
fit2cloud1panel< 1.10.3-lts1.10.3-lts
github.com1panel-dev_1panel>= 0 < 1.10.3-lts1.10.3-lts
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.