CVE-2023-39966

    Dashboard / Vulnerabilities / CVE-2023-39966

    CVE-2023-39966

    Published: 10 Aug 2023Last Modified: 12 Aug 2026

    Summary: 1Panel arbitrary file write vulnerability exists in the background

    Details: 1Panel is an open source Linux server operation and maintenance management panel. In version 1.4.3, an arbitrary file write vulnerability could lead to direct control of the server. In the `api/v1/file.go` file, there is a function called `SaveContentthat,It `recieves JSON data sent by users in the form of a POST request. And the lack of parameter filtering allows for arbitrary file write operations. Version 1.5.0 contains a patch for this issue.

    Affected packages

    Package

    Name:

    Purl:

    Affected ranges

    Type: GIT

    Events:

    Introduced- 86ba53d6ec35fe2f0f3bcdb8c8d3c4cb2ef4cf1b

    Affected versions

    1.4.3

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    CVE-2023-39966 | CVE-DB