usmannasir cyberpanel是usmannasir的Web中间件。 usmannasir CyberPanel 1.9.1及之前版本存在授权问题漏洞,该漏洞源于IncBackups application的incremental-backup handlers中存在不安全的直接对象引用,可能导致经过身份验证的用户通过提供全局顺序的IncJob整数ID访问或操作其他租户的备份资源,攻击者可以枚举备份ID读取其他租户的备份元数据、删除备份快照或以root权限触发未授权的备份恢复。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| usmannasir | cyberpanel | ≤ 1.9.1 |
affected |
b1984603f9b0099b39bca46fea176e53b6d4d601 |
unaffected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| usmannasir | cyberpanel | 0 ~ 1.9.1 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No comments yet