Showing 2 vulnerabilities on this page for ZPanel

Signals CISA KEV Ransomware Nuclei
ZPanel Project vulnerability results
VulnerabilityTitle and contextCVSSEPSSPoCsSignalsSTIX action

ZPanel zsudo Local Privilege Escalation

ZPanel includes a helper binary named zsudo, intended to allow restricted privilege escalation for administrative tasks. However, when misconfigured in /etc/sudoers, zsudo can be invoked by low-privileged users to execute arbitrary commands as root. This flaw enables local attackers with shell access to escalate privileges by writing a payload to a writable directory and executing it via zsudo. The vulnerability is particularly impactful in post-exploitation scenarios following web server compro

CWE-269Aug 4, 2025
CVSS8.5v4.0EPSS0.265%PoCs2SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

ZPanel <= 10.0.0.2 htpasswd Module Username Command Execution

A remote command execution vulnerability exists in ZPanel version 10.0.0.2 in its htpasswd module. When creating .htaccess files, the inHTUsername field is passed unsanitized to a system() call that invokes the system’s htpasswd binary. By injecting shell metacharacters into the username field, an authenticated attacker can execute arbitrary system commands. Exploitation requires a valid ZPanel account—such as one in the default Users, Resellers, or Administrators groups—but no elevated privileg

CWE-78Aug 1, 2025
CVSS8.7v4.0EPSS1.08%PoCs1SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX