CloudPanel 2 before 2.3.1 has insecure file-manager cookie authentication.
The product relies on the existence or values of cookies when performing security-critical operations, but it does not properly ensure that the setting is valid for the associated user.
Link | Tags |
---|---|
https://www.cloudpanel.io/docs/v2/changelog/ | release notes |
https://www.datack.my/fallingskies-cloudpanel-0-day/ | exploit |
https://github.com/datackmy/FallingSkies-CVE-2023-35885 | exploit |