CVE-2024-53376
HIGHCyberPanel < 2.3.8 - Authenticated OS Command Injection via phpSelection Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2024-53376. PoCs published by ThottySploity.
AI-analyzed exploit summary This repository contains a functional exploit for CVE-2024-53376, an authenticated OS command injection vulnerability in CyberPanel versions < 2.3.8. The exploit leverages the /websites/submitWebsiteCreation endpoint to execute arbitrary commands via the phpSelection parameter.
Description
CyberPanel before 2.3.8 allows remote authenticated users to execute arbitrary commands via shell metacharacters in the phpSelection field to the websites/submitWebsiteCreation URI.
Exploits (1)
This repository contains a functional exploit for CVE-2024-53376, an authenticated OS command injection vulnerability in CyberPanel versions < 2.3.8. The exploit leverages the /websites/submitWebsiteCreation endpoint to execute arbitrary commands via the phpSelection parameter.
References (3)
Scores
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H