CVE-2022-48079
CRITICALMengnai Aapanel Host System - Unrestricted File Upload
Title source: ruleDescription
Monnai aaPanel host system v1.5 contains an access control issue which allows attackers to escalate privileges and execute arbitrary code via uploading a crafted PHP file to the virtual host directory of the system.
References (3)
Core 3
Core References
Various Sources
https://blog.luckysix.cc/2022/12/22/CVE-2022-48079--%E6%A2%A6%E5%A5%88%E5%AE%9D%E5%A1%94%E4%B8%BB%E6%9C%BA%E7%B3%BB%E7%BB%9FRCE/
Vendor Advisory
http://mf.mengnai.top/
Exploit, Third Party Advisory
https://thanatosxingyu.github.io/
Scores
CVSS v3
9.8
EPSS
0.0145
EPSS Percentile
80.9%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CISA SSVC
Vulnrichment
Exploitation
poc
Automatable
yes
Technical Impact
total
Details
CWE
CWE-434
Status
published
Products (1)
mengnai/aapanel_host_system
1.5
Published
Feb 02, 2023
Tracked Since
Feb 18, 2026