CVE-2024-53376 Information

Description

CyberPanel before 2.3.8 allows remote authenticated users to execute arbitrary commands via shell metacharacters in the phpSelection field to the websites/submitWebsiteCreation URI.

Reference

https://github.com/ThottySploity/CVE-2024-53376 https://github.com/ThottySploity/CVE-2024-53376/blob/aa306187323bd1127d56803cb34cac8820b61484/cyberpanel.py#L70 https://thottysploity.github.io/posts/cve-2024-53376

Share on: