216.73.216.233

CVE-2024-39907

· Published 18/07/2024 16:15 · Modified 18/07/2024 16:15

Labels: CVE-2024-39907 2024-07-18CVE-2024-39907CWE-89[email protected]

Essential information

Published
18/07/2024 16:15
Modified
18/07/2024 16:15
Author
Creator
CVSS
9.8 CRITICAL (v3.1)
CISA KEV
No
CWE
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CVSS metrics

Description

1Panel is a web-based linux server management control panel. There are many sql injections in the project, and some of them are not well filtered, leading to arbitrary file writes, and ultimately leading to RCEs. These sql injections have been resolved in version 1.10.12-tls. Users are advised to upgrade. There are no known workarounds for these issues.

NVD status

Status
Received — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

References