'; } else{ echo ''; } echo '
|
|||
Release Date:2025/9/15
Rule Name:CVE-2024-51378:Cyberpanel getresetstatus Remote Code Execution Vulnerability
Severity:critical
CVE ID:CVE-2024-51387
Descripiton:
|
Cyberpanel is an open source Web control panel. It provides an user-friendly user interface for managing websites, emails, databases, FTP accounts and more. Cyberpanel is designed to simplify the task of website management and make it easy for non-technical users to manage their online resources. /dns/getresetstatus and /ftp/getresetstatus endpoints have a remote code execution vulnerability, which allows attackers execute arbitrary command by bypassing secMiddleware. Version 2.3.5 and 2.3.6 are affected by the vulnerability. rule supports to defend the A9: Using Components with Known Vulnerabilities of OWASP TOP 10 - 2021.
Other reference:None
Solution:
|
Update vendor patches.