PT-2023-25643 · Unknown · Cloudpanel

Mohammad Zulfiqar

·

Published

2023-06-25

·

Updated

2023-07-03

·

CVE-2023-36630

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions CloudPanel versions prior to 2.3.1
Description The issue is related to insecure file upload, which leads to privilege escalation and authentication bypass. This allows unauthorized access and elevated privileges.
Recommendations For versions prior to 2.3.1, update to version 2.3.1 or later to resolve the issue. As a temporary workaround, consider restricting file uploads or implementing additional authentication measures to minimize the risk of exploitation.

Exploit

Fix

Unrestricted File Upload

Weakness Enumeration

Related Identifiers

CVE-2023-36630

Affected Products

Cloudpanel