PT-2024-9377 · Unknown · Cyberpanel

Published

2024-10-23

·

Updated

2026-02-01

·

CVE-2024-51567

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions: CyberPanel versions through 2.3.6 and (unpatched) 2.3.7
Description: The issue is related to the upgrademysqlstatus function in CyberPanel, which has inadequate authentication procedures. This allows a remote attacker to bypass authentication and execute arbitrary commands via the /dataBases/upgrademysqlstatus endpoint by using shell metacharacters in the statusfile property. The vulnerability has been exploited in the wild in October 2024 by PSAUX.
Recommendations: For versions through 2.3.6 and (unpatched) 2.3.7, consider disabling the upgrademysqlstatus function in databases/views.py to prevent exploitation until a patch is available. Restrict access to the /dataBases/upgrademysqlstatus endpoint to minimize the risk of exploitation. Avoid using the statusfile property in the affected endpoint until the issue is resolved.

Exploit

Fix

Missing Authentication

Incorrect Default Permissions

Weakness Enumeration

Related Identifiers

BDU:2024-11067
CVE-2024-51567

Affected Products

Cyberpanel