High severity8.8NVD Advisory· Published Jun 14, 2024· Updated Jun 17, 2026
CVE-2024-24320
CVE-2024-24320
Description
Directory Traversal vulnerability in Mgt-commerce CloudPanel v.2.0.0 thru v.2.4.0 allows a remote attacker to obtain sensitive information and execute arbitrary code via the service parameter of the load-logfiles function.
Affected products
3cpe:2.3:a:mgt-commerce:cloudpanel:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:mgt-commerce:cloudpanel:*:*:*:*:*:*:*:*range: >=2.0.0,<=2.4.0
- (no CPE)
- Range: v.2.0.0 thru v.2.4.0
Patches
Vulnerability mechanics
References
1- datack.my/cloudpanel-v2-0-0-v2-4-0-authenticated-user-session-hijacking-cve-2024-24320/nvdExploitThird Party Advisory
News mentions
0No linked articles in our index yet.