ID:10940 - Exploit for Improper Authentication in CyberPanel - CVE-2024-51378

 
Main Vulnerability Database Exploits ID:10940 - Exploit for Improper Authentication in CyberPanel - CVE-2024-51378

ID:10940 - Exploit for Improper Authentication in CyberPanel - CVE-2024-51378

Published: December 5, 2024


Vulnerability identifier: #VU99597
Vulnerability risk: Critical
CVE-ID: CVE-2024-51378
CWE-ID: CWE-287
Exploitation vector: Remote access
Vulnerable software:
CyberPanel

Link to public exploit:


Vulnerability description

The vulnerability allows a remote attacker to bypass authentication process.

The vulnerability exists due to improper authentication within getresetstatus in dns/views.py. A remote non-authenticated attacker can send a specially crafted HTTP POST request to the  /dns/getresetstatus or /ftp/getresetstatus endpoints, bypass authentication and execute arbitrary OS commands on the system.


Remediation

Install updates from vendor's repository.