PT-2024-9697 · Unknown · Cyberpanel

·

CVE-2024-53376

·

Published

2024-10-30

·

Updated

2025-09-05

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions CyberPanel versions prior to 2.3.8
Description The issue exists due to the lack of measures to neutralize special elements, allowing a remote attacker to execute arbitrary commands using a specially crafted HTTP OPTIONS request. This can be achieved by exploiting shell metacharacters in the phpSelection field to the "websites/submitWebsiteCreation" URI. It is estimated that over 870,000 services are potentially affected.
Recommendations For versions prior to 2.3.8, update to version 2.3.8 or later to resolve the issue. As a temporary workaround, consider restricting access to the phpSelection field in the "websites/submitWebsiteCreation" URI until a patch is available. Avoid using the phpSelection field in the affected API endpoint until the issue is resolved.

Exploit

Fix

OS Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2024-11417
CVE-2024-53376

Affected Products

Cyberpanel