Vulnerability Description
aaPanel through 6.8.12 allows Cross-Site WebSocket Hijacking (CSWH) involving OS commands within WebSocket messages at a ws:// URL for /webssh (the victim must have configured Terminal with at least one host). Successful exploitation depends on the browser used by a potential victim (e.g., exploitation can occur with Firefox but not Chrome).
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Aapanel | Aapanel | <= 6.8.12 |
References
- https://github.com/aaPanel/aaPanel/issues/74ExploitThird Party Advisory
- https://ssd-disclosure.com/ssd-advisory-aapanel-cswh-to-rce/ExploitThird Party Advisory
- https://github.com/aaPanel/aaPanel/issues/74ExploitThird Party Advisory
- https://ssd-disclosure.com/ssd-advisory-aapanel-cswh-to-rce/ExploitThird Party Advisory
FAQ
What is CVE-2021-37840?
CVE-2021-37840 is a vulnerability with a CVSS score of 8.8 (HIGH). aaPanel through 6.8.12 allows Cross-Site WebSocket Hijacking (CSWH) involving OS commands within WebSocket messages at a ws:// URL for /webssh (the victim must have configured Terminal with at least o...
How severe is CVE-2021-37840?
CVE-2021-37840 has been rated HIGH with a CVSS base score of 8.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2021-37840?
Check the references section above for vendor advisories and patch information. Affected products include: Aapanel Aapanel.