在 CyberPanel 3.0.0 之前的版本中存在一个路径遍历漏洞。该漏洞允许已认证的管理员通过向 cloudAPI 的 ReadReport 端点提供未经过清理的文件路径,从而读取服务器文件系统中的任意文件。攻击者可以在 JSON 请求体中操纵 reportFile 参数,该参数会被直接传递到 cloudManager.py 中的 open() 函数,而未经过任何验证或白名单检查。这使得攻击者能够遍历并访问 CyberPanel 进程(以 root 权限运行)可读取的任何文件,包括凭据文件、SSL 和 SSH
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| usmannasir | cyberpanel | < 3.0.0 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| usmannasir | cyberpanel | 0 ~ 3.0.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet