← Πίσω στην αναζήτηση CVE

CVE-2026-71964

Περιγραφή

CyberPanel 2.4.3, fixed in commit eca0c3c, contains an arbitrary file read vulnerability in the file manager component that allows authenticated attackers to read sensitive system files by uploading a crafted ZIP archive containing symbolic links. Attackers can exploit the application-s failure to validate symlinks before extraction, causing symbolic links targeting arbitrary filesystem paths outside the user-s home directory to persist on disk and be accessed through the web interface.

CVSS 6.5EPSS 0.317%Κίνδυνος 0.67
Προβολή πηγής
Δημοσίευση
2026-08-10 19:17:31
Τελευταία τροποποίηση
2026-08-11 15:17:35
Διάνυσμα
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N