← back
CVE-2023-39964highobserved exploitationCWE-22

1Panel O&M management panel has a background arbitrary file reading vulnerability

43Vexday Risk Score

Prioritize patching. It exploitation observed by VulnCheck.

ssvc Actcvss 7.5epss 1.0%
from disclosure to weapon
Published on NVDAug 10
VulnCheck+970d
exploitation probability
1.0%top 40% of all CVEs
observed exploitation
yesVulnCheck
1Panel is an open source Linux server operation and maintenance management panel. In version 1.4.3, arbitrary file reads allow an attacker to read arbitrary important configuration files on the server. In the `api/v1/file.go` file, there is a function called `LoadFromFile`, which directly reads the file by obtaining the requested path `parameter[path]`. The request parameters are not filtered, resulting in a background arbitrary file reading vulnerability. Version 1.5.0 has a patch for this issue.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Affected products
1Panel-dev · 1Panel