CVE-2023-39964

    Dashboard / Vulnerabilities / CVE-2023-39964

    CVE-2023-39964

    Published: 10 Aug 2023Last Modified: 12 Aug 2026

    Summary: 1Panel O&M management panel has a background arbitrary file reading vulnerability

    Details: 1Panel is an open source Linux server operation and maintenance management panel. In version 1.4.3, arbitrary file reads allow an attacker to read arbitrary important configuration files on the server. In the `api/v1/file.go` file, there is a function called `LoadFromFile`, which directly reads the file by obtaining the requested path `parameter[path]`. The request parameters are not filtered, resulting in a background arbitrary file reading vulnerability. Version 1.5.0 has a patch for this issue.

    Affected packages

    Package

    Name:

    Purl:

    Affected ranges

    Type: GIT

    Events:

    Introduced- 86ba53d6ec35fe2f0f3bcdb8c8d3c4cb2ef4cf1b

    Affected versions

    1.4.3

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    CVE-2023-39964 | CVE-DB