Description
CloudPanel has an authentication bypass vulnerability. An attacker can bypass the authentication with a specially crafted HTTP request and get access to the file-manager.
Remediation
Upgrade to the latest version of CloudPanel
References
Related Vulnerabilities
WebLogic CVE-2019-2646 Vulnerability (CVE-2019-2646)
phpMyAdmin Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2013-4998)
XWiki Improper Privilege Management Vulnerability (CVE-2023-26475)
MySQL CVE-2022-21316 Vulnerability (CVE-2022-21316)
MediaWiki Loop with Unreachable Exit Condition ('Infinite Loop') Vulnerability (CVE-2021-42040)