Executive brief
CyberPanel contains an authentication bypass and OS command injection vulnerability in the getresetstatus function within dns/views.py and ftp/views.py. Remote attackers can bypass security middleware by using non-POST requests and execute arbitrary commands via shell metacharacters in the statusfile property.
Affected products
- CyberPanel CyberPanel through 2.3.6 and unpatched 2.3.7 (fixed in 1c0c6cb / 2.3.8)
Timeline
- 2024-10-21: exploited: Exploited in the wild by PSAUX ransomware actors.
- 2024-12-04: kev added: Added to CISA Known Exploited Vulnerabilities (KEV) catalog.
- 2024-12-04: disclosed: NVD publication date.
- 2024-10-27: patched: Vendor commit 1c0c6cbcf71abe573da0b5fddfb9603e7477f683 addresses the issue.