漏洞标题
1Panel 背景中的任意文件写入漏洞存在
漏洞描述信息
后台存在面板任意文件写入漏洞
CVSS信息
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
漏洞类别
对路径名的限制不恰当(路径遍历)
漏洞标题
1Panel arbitrary file write vulnerability exists in the background
漏洞描述信息
1Panel is an open source Linux server operation and maintenance management panel. In version 1.4.3, an arbitrary file write vulnerability could lead to direct control of the server. In the `api/v1/file.go` file, there is a function called `SaveContentthat,It `recieves JSON data sent by users in the form of a POST request. And the lack of parameter filtering allows for arbitrary file write operations. Version 1.5.0 contains a patch for this issue.
CVSS信息
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
漏洞类别
授权机制缺失
漏洞标题
1Panel 安全漏洞
漏洞描述信息
1Panel是中国1panel社区的一个开源的Linux服务器运维管理面板。 1Panel 1.4.3版本存在安全漏洞,该漏洞源于缺乏对参数的过滤。
CVSS信息
N/A
漏洞类别
其他