CVE-2024-39907

CRITICAL NUCLEI

Fit2cloud 1panel < 1.10.12-lts - SQL Injection

Title source: rule

Description

1Panel is a web-based linux server management control panel. There are many sql injections in the project, and some of them are not well filtered, leading to arbitrary file writes, and ultimately leading to RCEs. These sql injections have been resolved in version 1.10.12-tls. Users are advised to upgrade. There are no known workarounds for these issues.

Nuclei Templates (1)

1Panel SQL Injection - Authenticated
CRITICALVERIFIEDby iamnoooob,rootxharsh,pdresearch
FOFA: icon_hash="1300107149" || icon_hash="1453309674" || cert.issuer.cn="1Panel Intermediate CA"

Scores

CVSS v3 9.8
EPSS 0.8470
EPSS Percentile 99.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-89
Status published
Products (2)
1Panel-dev/1Panel 0 - 1.10.12-tlsGo
fit2cloud/1panel 1.10.9-lts - 1.10.12-lts
Published Jul 18, 2024
Tracked Since Feb 18, 2026