PT-2018-9261 · Ajenti · Ajenti

Published

2018-03-13

·

Updated

2018-04-06

·

CVE-2018-1000082

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: Ajenti version 2
Description: The issue is related to a Cross-Site Request Forgery (CSRF) vulnerability in the command execution panel of the tool used to manage the server. This can result in code execution on the server. The attack is exploitable via a CSRF, which requires victim interaction. When the victim accesses the infected trigger of the CSRF, any code that matches the victim's privileges on the server can be executed.
Recommendations: For Ajenti version 2, consider disabling the command execution panel until a patch is available to prevent potential code execution on the server. Restrict access to the server management tool to minimize the risk of exploitation. Avoid using the tool for critical operations until the issue is resolved.

Exploit

Fix

CSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2018-1000082
PYSEC-2018-111

Affected Products

Ajenti