Descrição
CyberPanel 2.4.3, fixed in commit eca0c3c, contains an arbitrary file read vulnerability in the file manager component that allows authenticated attackers to read sensitive system files by uploading a crafted ZIP archive containing symbolic links. Attackers can exploit the application-s failure to validate symlinks before extraction, causing symbolic links targeting arbitrary filesystem paths outside the user-s home directory to persist on disk and be accessed through the web interface.
CVSS 6.5EPSS 0.317%Risco 0.67
Ver fonte- Publicação
- 2026-08-10 19:17:31
- Última alteração
- 2026-08-11 15:17:35
- Vetor
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N