CyberPanel Security Update Advisory (CVE-2024-53376)

Overview

 

An update has been released to address vulnerabilities in CyberPanel. Users of the affected versions are advised to update to the latest version.
 

 

Affected Products

 

 

CVE-2024-53376

  • CyberPanel versions: ~ 2.3.8 (excluded)

 

 

Resolved Vulnerabilities

 

Vulnerability that allows remote authenticated users to execute arbitrary commands via shell metacharacters in the phpSelection field of the /websites/submitWebsiteCreation URI (CVE-2024-53376)

 

 

Vulnerability Patches

Vulnerability Patches have been made available in the latest update. Please follow the instructions on the Referenced Sites to update to the latest Vulnerability Patches version.

 

 

CVE-2024-53376

  • CyberPanel version: 2.3.8

 

 

Referenced Sites

 

[1] CVE-2024-53376 Detail

https://nvd.nist.gov/vuln/detail/CVE-2024-53376

[2] github/CVE-2024-53376

https://github.com/ThottySploity/CVE-2024-53376

[3] CVE-2024-53376 CyberPanel Authenticated RCE

https://thottysploity.github.io/posts/cve-2024-53376/