A Command injection vulnerability in requestLetsEncryptSslWithDnsChallenge in NginxProxyManager 2.11.3 allows an attacker to achieve remote code execution via Add Let's Encrypt Certificate. NOTE: this is not part of any NGINX software shipped by F5.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:LJc21 nginx Proxy Manager
APPJc212.11.3
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
RCESQLi
CWE
Related vulnerabilities
CVE-2024-46256CRITICAL9.8PL ✓same product
Command injection w Nginx Proxy Manager — RCE przez funkcję Let's Encrypt
CVE-2023-27224CRITICAL9.8PL ✓same product
RCE w NginxProxyManager przez wstrzyknięcie skryptu Lua do konfiguracji
CVE-2024-39935HIGH8.8same product
jc21 NGINX Proxy Manager before 2.11.3 allows backend/internal/certificate.js OS command injection by an authe...
CVE-2023-23596HIGH8.8same product
jc21 NGINX Proxy Manager through 2.9.19 allows OS command injection. When creating an access list, the backend...
CVE-2025-50579MEDIUM5.3same product
A CORS misconfiguration in Nginx Proxy Manager v2.12.3 allows unauthorized domains to access sensitive data, p...