Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Lpanel 1.59 and earlier, and other versions before 1.597, allows remote authenticated users to modify certain critical variables and (1) modify DNS settings for arbitrary domains via the domain parameter to diagnose.php, (2) close, open, or respond to arbitrary support tickets via the close, open, or pid parameter to view_ticket.php, (3) obtain sensitive information on arbitrary invoices via the inv parameter to viewreceipt.php, or (4) modify domain information for arbitrary domains via the editdomain parameter to domains.php.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
LPanel多个输入验证漏洞
Vulnerability Description
Lpanel 1.59和更早版本,以及1.597之前的其他版本,可让远程认证的用户修改某些重要变量,并(1)通过diagnose.php的domain参数修改任意域的DNS设置,(2)通过view_ticket.php的close、open或pid参数关闭、打开或响应任意支持的凭证,(3)通过viewreceipt.php的inv参数获取关于任意发票的敏感信息,或(4)通过domains.php的editdomain参数修改任意域的域信息。
CVSS Information
N/A
Vulnerability Type
N/A