← Back to browse · API

CVE-2024-51568

Severity
CRITICAL
CVSS
10.0
EPSS
0.4546
Risk score
55.91
CISA KEV
No
PoC
No
Published
2024-10-29
Modified
2024-10-30
First seen
2026-08-07
Aliases
EUVD-2024-45405, GHSA-Q2HV-8PRH-HR3R
Products
n/a:n/a n/a
Sources
euvd EUVD-2024-45405

Description

CyberPanel (aka Cyber Panel) before 2.3.5 allows Command Injection via completePath in the ProcessUtilities.outputExecutioner() sink. There is /filemanager/upload (aka File Manager upload) unauthenticated remote code execution via shell metacharacters.

References