Vulnerabilities
Vulnerable Software
Fit2cloud:  >> 1panel  >> 1.10.2-lts  Security Vulnerabilities
1Panel is an open source Linux server operation and maintenance management panel. Prior to v1.10.3-lts, there are many command injections in the project, and some of them are not well filtered, leading to arbitrary file writes, and ultimately leading to RCEs. The mirror configuration write symbol `>` can be used to achieve arbitrary file writing. This vulnerability is fixed in v1.10.3-lts.
CVSS Score
6.5
EPSS Score
0.022
Published
2024-05-14
1Panel is an open source Linux server operation and maintenance management panel. The password verification in the source code uses the != symbol instead hmac.Equal. This may lead to a timing attack vulnerability. This vulnerability is fixed in 1.10.3-lts.
CVSS Score
3.9
EPSS Score
0.001
Published
2024-04-18


Contact Us

Shodan ® - All rights reserved