Record summary

EIP currently links 1 Nuclei template to CVE-2024-39907.

Description

1Panel is a web-based linux server management control panel. There are many sql injections in the project, and some of them are not well filtered, leading to arbitrary file writes, and ultimately leading to RCEs. These sql injections have been resolved in version 1.10.12-tls. Users are advised to upgrade. There are no known workarounds for these issues.

Description source: CVE List

Exploitation context

Available material

Nuclei templates
1

CISA SSVC decision

ExploitationPoC
AutomatableYes
Technical impactTotal

CISA Coordinator · SSVC 2.0.3 · Evaluated Jul 18, 2024 · Source: CVE List

Affected products and versions

3
ProductSourceVersion rangeStatus
CVE List>= 1.10.9-tls, < 1.10.12-tlsaffected

Default status: unknown

CVE ListBefore 1.10.12-ltsaffected

github.com/1Panel-dev/1Panel

Browse Go / github.com/1Panel-dev/1Panel
GitHub AdvisoryBefore 1.10.12-tls · Fixed in 1.10.12-tlsaffected

Nuclei templates

1
ProjectDiscoveryCRITICAL1Panel SQL Injection - AuthenticatedCVSS 9.8

1Panel is a web-based linux server management control panel. There are many sql injections in the project, and some of them are not well filtered, leading to arbitrary file writes, and ultimately leading to RCEs. These sql injections have been resolved in version 1.10.12-tls. Users are advised to upgrade. There are no known workarounds for these issues.

Impact

Authenticated attackers can exploit SQL injection vulnerabilities to execute arbitrary SQL queries, write files, and achieve remote code execution.

Remediation

Upgrade to 1Panel version 1.10.12-lts or later.

WeaknessesCWE-89
Authorsiamnoooob, rootxharsh, pdresearch
Template tagscvecve2024sqli1panelauthenticatedvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CPE: cpe:2.3:a:fit2cloud:1panel:*:*:*:*:*:*:*:*
FOFA: icon_hash="1300107149" || icon_hash="1453309674" || cert.issuer.cn="1Panel Intermediate CA"

Source: ProjectDiscovery

References

4