Junglewise Threat Intelligence

CVE-2024-51567: CyberPanel Incorrect Default Permissions Vulnerability

CVE-2024-51567 · Severity: critical · CVSS 10 · Exploited in the wild · Published 2024-11-07

Technologies: Cyberpersons CyberPanel. Vendors: Cyberpersons, CyberPanel.

Executive brief

CyberPanel contains a critical vulnerability in the upgrademysqlstatus component of databases/views.py that allows remote, unauthenticated attackers to execute arbitrary commands as root. The flaw exists because secMiddleware only filters POST requests, allowing attackers to bypass authentication via GET requests and inject shell metacharacters into the statusfile property.

Affected products

  • CyberPanel CyberPanel through 2.3.6 and unpatched 2.3.7

Timeline

  • 2024-10-27: disclosed: Public exploit and code review published by dreyand.rs
  • 2024-10-29: patched: Fix committed in GitHub (5b08cd6)
  • 2024-10-30: exploited: Observed in the wild by PSAUX ransomware actors
  • 2024-11-07: kev added: Added to CISA Known Exploited Vulnerabilities Catalog

Related threats