CVE-2023-39966

1

Panel is an open source Linux server operation and maintenance management panel. In version 1.4.3, an arbitrary file write vulnerability could lead to direct control of the server. In the `api/v1/file.go` file, there is a function called `SaveContentthat,It `recieves JSON data sent by users in the form of a POST request. And the lack of parameter filtering allows for arbitrary file write operations. Version 1.5.0 contains a patch for this issue.

Configurations

Configuration 1 (hide)

cpe:2.3:a:fit2cloud:1panel:1.4.3:*:*:*:*:*:*:*

History

21 Nov 2024, 08:16

Type Values Removed Values Added
References () https://github.com/1Panel-dev/1Panel/releases/tag/v1.5.0 - Product, Release Notes () https://github.com/1Panel-dev/1Panel/releases/tag/v1.5.0 - Product, Release Notes
References () https://github.com/1Panel-dev/1Panel/security/advisories/GHSA-hf7j-xj3w-87g4 - Exploit, Vendor Advisory () https://github.com/1Panel-dev/1Panel/security/advisories/GHSA-hf7j-xj3w-87g4 - Exploit, Vendor Advisory
CVSS v2 : unknown
v3 : 9.8
v2 : unknown
v3 : 7.5

Information

Published : 2023-08-10 18:15

Updated : 2024-11-21 08:16


NVD link : CVE-2023-39966

Mitre link : CVE-2023-39966

CVE.ORG link : CVE-2023-39966


JSON object : View

Products Affected
CWE
CWE-862

Missing Authorization