CyberPanel 2.4.3 至 2.4.5 版本暴露了未认证的 AI 扫描器调试端点,这些端点会泄露管理员用户名、API 密钥前缀、扫描标识符、目标域名以及账户元数据。未经身份验证的攻击者可以枚举面板管理员及近期的扫描器活动,从而对多租户部署环境进行资产梳理,并为后续的后续攻击提供支持。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| usmannasir | cyberpanel | 2.4.3 ~ 2.4.6 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet