Junglewise Threat Intelligence

CVE-2024-51378: CyberPanel Incorrect Default Permissions Vulnerability

CVE-2024-51378 · Severity: critical · CVSS 9.8 · Exploited in the wild · Published 2024-12-04

Technologies: Cyberpersons CyberPanel. Vendors: Cyberpersons.

Executive brief

CyberPanel contains an authentication bypass and OS command injection vulnerability in the getresetstatus function within dns/views.py and ftp/views.py. Remote attackers can bypass security middleware by using non-POST requests and execute arbitrary commands via shell metacharacters in the statusfile property.

Affected products

  • CyberPanel CyberPanel through 2.3.6 and unpatched 2.3.7 (fixed in 1c0c6cb / 2.3.8)

Timeline

  • 2024-10-21: exploited: Exploited in the wild by PSAUX ransomware actors.
  • 2024-12-04: kev added: Added to CISA Known Exploited Vulnerabilities (KEV) catalog.
  • 2024-12-04: disclosed: NVD publication date.
  • 2024-10-27: patched: Vendor commit 1c0c6cbcf71abe573da0b5fddfb9603e7477f683 addresses the issue.

Related threats