CVE-2024-27288Medium· 6.3▾ Sunlit1Panel open source panel project has an unauthorized vulnerability.
▾ Sunlit zone — Low / medium · no exploitation signal
impact 34.7 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Sep 12.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via OSV
Last analysed / modified upstream
0.5%
The steps are as follows:
Access https://IP:PORT/ in the browser, which prompts the user to access with a secure entry point.
Use Burp to intercept:
When opening the browser and entering the URL (allowing the first intercepted packet through Burp), the following is displayed:
It is found that in this situation, we can access the console page (although no data is returned and no modification operations can be performed)."
Affected versions: <= 1.10.0-lts
The vulnerability has been fixed in v1.10.1-lts.
It is recommended to upgrade the version to 1.10.1-lts.
If you have any questions or comments about this advisory:
Open an issue in https://github.com/1Panel-dev/1Panel Email us at [email protected]
github.com/1Panel-dev/1Panel < 1.10.1-ltsUpgrade to a patched release:
github.com/1Panel-dev/1Panel 1.10.1-ltsConnected by shared product, vendor, weakness, or advisory.
CVE-2023-39965Medium· 6.51Panel Arbitrary File Download vulnerability
CVE-2023-36458Medium· 6.31Panel vulnerable to command injection when entering the container terminal
CVE-2024-30257Medium· 5.91Panel's password verification is suspected to have a timing attack vulnerability
CVE-2024-39907Critical· 9.81Panel has an SQL injection issue related to the orderBy clause
CVE-2026-79919Medium· 6.3MaxKB is an open-source AI assistant for enterprise
CVE-2026-79918Medium· 6.3MaxKB is an open-source AI assistant for enterprise