CVE-2024-39907

Source
https://nvd.nist.gov/vuln/detail/CVE-2024-39907
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-39907.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2024-39907
Aliases
Published
2024-07-18T15:31:30.892Z
Modified
2025-11-19T17:34:17.831273Z
Severity
  • 9.8 (Critical) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
a sqlinjection in 1Panel
Details

1Panel is a web-based linux server management control panel. There are many sql injections in the project, and some of them are not well filtered, leading to arbitrary file writes, and ultimately leading to RCEs. These sql injections have been resolved in version 1.10.12-tls. Users are advised to upgrade. There are no known workarounds for these issues.

Database specific
{
    "cwe_ids": [
        "CWE-89"
    ]
}
References

Affected packages

Git / github.com/1panel-dev/1panel

Affected ranges

Type
GIT
Repo
https://github.com/1panel-dev/1panel
Events