PT-2026-102397 · Unknown · Nginx Proxy Manager
CVSS v3.1
7.1
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Nginx Proxy Manager versions prior to 2.16.1
Description
Non-administrator users with manage permissions can inject arbitrary nginx directives because the software fails to restrict the
advanced config field to administrators. This allows attackers to implement malicious configurations, such as using alias directives to serve arbitrary files or manipulating routing for their assigned hosts.Recommendations
Update to version 2.16.1 or later.
Restrict access to the
advanced config field to only authorized administrator accounts.Fix
Incorrect Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Nginx Proxy Manager