CVE-2024-34352

MEDIUM

1Panel <1.10.3-lts - Command Injection

Title source: llm
STIX 2.1

Description

1Panel is an open source Linux server operation and maintenance management panel. Prior to v1.10.3-lts, there are many command injections in the project, and some of them are not well filtered, leading to arbitrary file writes, and ultimately leading to RCEs. The mirror configuration write symbol `>` can be used to achieve arbitrary file writing. This vulnerability is fixed in v1.10.3-lts.

References (1)

Core 1
Core References

Scores

CVSS v3 6.5
EPSS 0.0133
EPSS Percentile 67.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact total

Details

CWE
CWE-77
Status published
Products (2)
1Panel-dev/1Panel 0 - 1.10.3-ltsGo
fit2cloud/1panel < 1.10.3-lts
Published May 14, 2024
Tracked Since Feb 18, 2026