Executive brief
CyberPanel contains a critical vulnerability in the upgrademysqlstatus component of databases/views.py that allows remote, unauthenticated attackers to execute arbitrary commands as root. The flaw exists because secMiddleware only filters POST requests, allowing attackers to bypass authentication via GET requests and inject shell metacharacters into the statusfile property.
Affected products
- CyberPanel CyberPanel through 2.3.6 and unpatched 2.3.7
Timeline
- 2024-10-27: disclosed: Public exploit and code review published by dreyand.rs
- 2024-10-29: patched: Fix committed in GitHub (5b08cd6)
- 2024-10-30: exploited: Observed in the wild by PSAUX ransomware actors
- 2024-11-07: kev added: Added to CISA Known Exploited Vulnerabilities Catalog