CyberPanel Pre-Auth RCE Chain Lets Attackers Gain Server Shell via AI Scanner Flaws

Security researchers have disclosed a critical pre-authentication RCE chain in CyberPanel that could let attackers gain a shell on vulnerable hosting servers without valid credentials. The attack combines weaknesses in the platform’s AI Scanner functionality with stored cross-site scripting and abuse of cron jobs. The issue affects CyberPanel versions earlier than 2.4.4. CyberPanel is a […]

This article has been indexed from Cyber Security News

Read the original article: