PT-2023-26698 · Unknown · Django-Sspanel

Published

2023-08-03

·

Updated

2025-12-07

·

CVE-2023-38941

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions django-sspanel version 2022.2.2
Description The software contains a remote command execution (RCE) issue through the GoodsCreateView. post component within sspanel/admin view.py. The software, used in proxy services, is susceptible to hacks and compromises due to this and other known issues like information leaks.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

RCE

Command Injection

Weakness Enumeration

Related Identifiers

CVE-2023-38941

Affected Products

Django-Sspanel