HIGH🇵🇱 Wersja polska

CVE-2023-0391

CVSS 8.1v3.1pub. 2023-03-21upd. 2025-02-26

MGT-COMMERCE CloudPanel ships with a static SSL certificate to encrypt communications to the administrative interface, shared across every installation of CloudPanel. This behavior was observed in version 2.2.0. There has been no indication from the vendor this has been addressed in version 2.2.1.

CVSS Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
  • Mgt Commerce Cloudpanel

    APP
    Mgt-Commerce
    < 2.2.1
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References

Related vulnerabilities

CVE-2023-35885CRITICAL9.8PL ✓same product

CloudPanel 2: niebezpieczne uwierzytelnianie cookie w menedżerze plików

CVE-2024-24320HIGH8.8same product

Directory Traversal vulnerability in Mgt-commerce CloudPanel v.2.0.0 thru v.2.4.0 allows a remote attacker to ...

CVE-2023-46157HIGH8.8same product

File-Manager in MGT CloudPanel 2.0.0 through 2.3.2 allows the lowest privilege user to achieve OS command inje...

CVE-2023-36630HIGH8.8same product

In CloudPanel before 2.3.1, insecure file upload leads to privilege escalation and authentication bypass.

CVE-2023-33747HIGH7.8same product

CloudPanel v2.2.2 allows attackers to execute a path traversal.