Vulnerabilities
Vulnerable Software
Aapanel:  >> Aapanel  >> 6.2.1  Security Vulnerabilities
AAPanel v7.0.7 was discovered to contain an OS command injection vulnerability.
CVSS Score
6.5
EPSS Score
0.075
Published
2025-05-21
aaPanel through 6.8.12 allows Cross-Site WebSocket Hijacking (CSWH) involving OS commands within WebSocket messages at a ws:// URL for /webssh (the victim must have configured Terminal with at least one host). Successful exploitation depends on the browser used by a potential victim (e.g., exploitation can occur with Firefox but not Chrome).
CVSS Score
8.8
EPSS Score
0.004
Published
2021-08-02
aaPanel through 6.6.6 allows remote authenticated users to execute arbitrary commands via shell metacharacters in a modified /system?action=ServiceAdmin request (start, stop, or restart) to the setting menu of Sotfware Store.
CVSS Score
8.8
EPSS Score
0.027
Published
2020-06-21
aaPanel through 6.6.6 allows remote authenticated users to execute arbitrary commands via the Script Content box on the Add Cron Job screen.
CVSS Score
7.2
EPSS Score
0.056
Published
2020-06-18


Contact Us

Shodan ® - All rights reserved