Critical severity10.0NVD Advisory· Published Oct 29, 2024· Updated Jun 17, 2026
CVE-2024-51568
CVE-2024-51568
Description
CyberPanel (aka Cyber Panel) before 2.3.5 allows Command Injection via completePath in the ProcessUtilities.outputExecutioner() sink. There is /filemanager/upload (aka File Manager upload) unauthenticated remote code execution via shell metacharacters.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3cpe:2.3:a:cyberpanel:cyberpanel:*:*:*:*:*:*:*:*+ 2 more
- cpe:2.3:a:cyberpanel:cyberpanel:*:*:*:*:*:*:*:*range: <2.3.5
- (no CPE)
- (no CPE)range: <2.3.5
Patches
Vulnerability mechanics
References
4- dreyand.rs/code/review/2024/10/27/what-are-my-options-cyberpanel-v236-pre-auth-rcenvdExploitThird Party Advisory
- cwe.mitre.org/data/definitions/78.htmlnvdProduct
- cyberpanel.net/KnowledgeBase/home/change-logs/nvdRelease Notes
- cyberpanel.net/blog/cyberpanel-v2-3-5nvdRelease Notes
News mentions
0No linked articles in our index yet.