CVE-2024-51568
CRITICAL EXPLOITED RANSOMWARE NUCLEICyberPanel <2.3.5 - Command Injection
Title source: llmDescription
CyberPanel (aka Cyber Panel) before 2.3.5 allows Command Injection via completePath in the ProcessUtilities.outputExecutioner() sink. There is /filemanager/upload (aka File Manager upload) unauthenticated remote code execution via shell metacharacters.
Exploits (1)
nomisec
WORKING POC
1 stars
by jsnv-dev · remote
https://github.com/jsnv-dev/CVE-2024-51568---CyberPanel-Command-Injection-Nuclei-Template
Nuclei Templates (1)
CyberPanel - Command Injection
CRITICALVERIFIEDby s4e-io
Shodan:
http.html:"login to your cyberpanel account"
References (4)
Scores
CVSS v3
10.0
EPSS
0.9304
EPSS Percentile
99.8%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Details
VulnCheck KEV
2024-10-29
Ransomware Use
Confirmed
CWE
CWE-78
Status
published
Products (1)
cyberpanel/cyberpanel
< 2.3.5
Published
Oct 29, 2024
Tracked Since
Feb 18, 2026