« Volver al listado

Mgt-commerce

Mgt-commerce Cloudpanel: vulnerabilidades y CVE

Mgt-commerce Cloudpanel tiene 7 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 1 son críticas y 0 figuran en el catálogo de explotación activa de CISA.

CVE7
Últimos 12 meses0
Críticas1
Explotadas activamente0

Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología

Últimas vulnerabilidades

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2024-44765Media (6.5)0.66%—8 nov 2024
An Improper Authorization (Access Control Misconfiguration) vulnerability in MGT-COMMERCE GmbH CloudPanel v2.0.0 to v2.4.2 allows low-privilege users to bypass access controls and gain unauthorized access to sensitive…
CVE-2024-24320Alta (8.8)4.0%—14 jun 2024
Directory Traversal vulnerability in Mgt-commerce CloudPanel v.2.0.0 thru v.2.4.0 allows a remote attacker to obtain sensitive information and execute arbitrary code via the service parameter of the load-logfiles…
CVE-2023-46157Alta (8.8)2.3%—8 dic 2023
File-Manager in MGT CloudPanel 2.0.0 through 2.3.2 allows the lowest privilege user to achieve OS command injection by changing file ownership and changing file permissions to 4755.
CVE-2023-36630Alta (8.8)0.87%—25 jun 2023
In CloudPanel before 2.3.1, insecure file upload leads to privilege escalation and authentication bypass.
CVE-2023-35885Crítica (9.8)75%—20 jun 2023
CloudPanel 2 before 2.3.1 has insecure file-manager cookie authentication.
CVE-2023-33747Alta (7.8)0.47%—6 jun 2023
CloudPanel v2.2.2 allows attackers to execute a path traversal.
CVE-2023-0391Alta (8.1)0.60%—21 mar 2023
MGT-COMMERCE CloudPanel ships with a static SSL certificate to encrypt communications to the administrative interface, shared across every installation of CloudPanel. This behavior was observed in version 2.2.0. There…