CyberPanel 在 3.0.5 版本之前,未能强制在 API 端点实施双因素认证,使得攻击者能够利用基于密码生成的令牌来绕过 TOTP(基于时间的一次性密码)要求。攻击者一旦获取管理员的密码,即可推导出 API 令牌,从而无需第二因素即可执行管理操作或创建已认证的会话。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| usmannasir | cyberpanel | 0 ~ 3.0.5 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet