Executive brief
1Panel, an open-source control panel used to manage Linux servers and Docker containers, contains a security flaw in its web configuration settings. An attacker could trick an authenticated administrator into visiting a malicious website that silently changes the network port the control panel uses. This can result in a total loss of access for the legitimate administrator, causing service disruption and potentially exposing the management interface on an unintended network port.
Technical details
A Cross-Site Request Forgery (CSRF) vulnerability exists in 1Panel versions 1.10.33 - 2.0.15 due to a lack of anti-CSRF defenses on the port-change endpoint. The application fails to implement anti-CSRF tokens or validate Origin/Referer headers for sensitive configuration requests. An unauthenticated remote attacker can craft a malicious webpage that, when visited by an authenticated administrator, triggers a background request to change the web service's listening port. This results in a denial of service (DoS) as the original port becomes inaccessible and may expose the management interface on a port of the attacker's choosing. As of the advisory date, the maintainer has not addressed this vulnerability.
Affected products
- LXware 1Panel 1.10.33 - 2.0.15
Timeline
- 2025-12-10: advisory: Advisory published by VulnCheck