PT-2024-9697 · Unknown · Cyberpanel

Thottysploity

·

Published

2024-10-30

·

Updated

2025-09-05

·

CVE-2024-53376

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions CyberPanel versions prior to 2.3.8
Description The issue exists due to the lack of measures to neutralize special elements, allowing a remote attacker to execute arbitrary commands using a specially crafted HTTP OPTIONS request. This can be achieved by exploiting shell metacharacters in the phpSelection field to the "websites/submitWebsiteCreation" URI. It is estimated that over 870,000 services are potentially affected.
Recommendations For versions prior to 2.3.8, update to version 2.3.8 or later to resolve the issue. As a temporary workaround, consider restricting access to the phpSelection field in the "websites/submitWebsiteCreation" URI until a patch is available. Avoid using the phpSelection field in the affected API endpoint until the issue is resolved.

Exploit

Fix

OS Command Injection

Weakness Enumeration

Related Identifiers

BDU:2024-11417
CVE-2024-53376

Affected Products

Cyberpanel