CVE-2024-39907Critical· 9.8▾ AbyssalPoC available1Panel has an SQL injection issue related to the orderBy clause
▾ Abyssal zone — Critical with a public exploit or in-the-wild use
impact 53.9 · likelihood 5.8 · exploitation 12
A public proof-of-concept already exists for this vulnerability — see Exploit availability below.
Public exploit / PoC code seen in 1 source. Availability, not in-the-wild use.
Exploit-prediction probability, daily snapshots since Sep 12.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via OSV
Last analysed / modified upstream
29%
Nuclei ×1 (last check)
There are many sql injections in the project, and some of them are not well filtered, leading to arbitrary file writes, and ultimately leading to RCEs. The proof is as follows
curl 'http://api:30455/api/v1/hosts/command/search' {"page":1,"pageSize":10,"groupID":0,"orderBy":"3","order":"ascending","name":"a"} <img width="664" alt="image" src="https://github.com/1Panel-dev/1Panel/assets/129351704/250d5a2a-cb32-44dc-9831-86dbc2f2b43f"> for example as picture . just change orderby‘s num we can know How many columns does the data table have.Parameters require strict whitelist filtering
RCE、data leak.
github.com/1Panel-dev/1Panel < 1.10.12-tlsUpgrade to a patched release:
github.com/1Panel-dev/1Panel 1.10.12-tlsConnected by shared product, vendor, weakness, or advisory.
CVE-2023-39965Medium· 6.51Panel Arbitrary File Download vulnerability
CVE-2023-36458Medium· 6.31Panel vulnerable to command injection when entering the container terminal
CVE-2024-30257Medium· 5.91Panel's password verification is suspected to have a timing attack vulnerability
CVE-2024-27288Medium· 6.31Panel open source panel project has an unauthorized vulnerability.
CVE-2026-77518Medium· 5.0MaxKB is an open-source AI assistant for enterprise
CVE-2026-77521Critical· 10.0MaxKB is an open-source AI assistant for enterprise