Mgt-commerce
Mgt-commerce Cloudpanel: vulnerabilidades y CVE
Mgt-commerce Cloudpanel tiene 7 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 1 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE7
Últimos 12 meses0
Críticas1
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2024-44765 | Media (6.5) | 0.66% | — | 8 nov 2024 | An Improper Authorization (Access Control Misconfiguration) vulnerability in MGT-COMMERCE GmbH CloudPanel v2.0.0 to v2.4.2 allows low-privilege users to bypass access controls and gain unauthorized access to sensitive… |
| CVE-2024-24320 | Alta (8.8) | 4.0% | — | 14 jun 2024 | Directory Traversal vulnerability in Mgt-commerce CloudPanel v.2.0.0 thru v.2.4.0 allows a remote attacker to obtain sensitive information and execute arbitrary code via the service parameter of the load-logfiles… |
| CVE-2023-46157 | Alta (8.8) | 2.3% | — | 8 dic 2023 | File-Manager in MGT CloudPanel 2.0.0 through 2.3.2 allows the lowest privilege user to achieve OS command injection by changing file ownership and changing file permissions to 4755. |
| CVE-2023-36630 | Alta (8.8) | 0.87% | — | 25 jun 2023 | In CloudPanel before 2.3.1, insecure file upload leads to privilege escalation and authentication bypass. |
| CVE-2023-35885 | Crítica (9.8) | 75% | — | 20 jun 2023 | CloudPanel 2 before 2.3.1 has insecure file-manager cookie authentication. |
| CVE-2023-33747 | Alta (7.8) | 0.47% | — | 6 jun 2023 | CloudPanel v2.2.2 allows attackers to execute a path traversal. |
| CVE-2023-0391 | Alta (8.1) | 0.60% | — | 21 mar 2023 | MGT-COMMERCE CloudPanel ships with a static SSL certificate to encrypt communications to the administrative interface, shared across every installation of CloudPanel. This behavior was observed in version 2.2.0. There… |