Vulnerability Description
Monnai aaPanel host system v1.5 contains an access control issue which allows attackers to escalate privileges and execute arbitrary code via uploading a crafted PHP file to the virtual host directory of the system.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Mengnai | Aapanel Host System | 1.5 |
Related Weaknesses (CWE)
References
- http://mf.mengnai.top/Vendor Advisory
- https://thanatosxingyu.github.io/ExploitThird Party Advisory
- http://mf.mengnai.top/Vendor Advisory
- https://thanatosxingyu.github.io/ExploitThird Party Advisory
- https://blog.luckysix.cc/2022/12/22/CVE-2022-48079--%E6%A2%A6%E5%A5%88%E5%AE%9D%
FAQ
What is CVE-2022-48079?
CVE-2022-48079 is a vulnerability with a CVSS score of 9.8 (CRITICAL). Monnai aaPanel host system v1.5 contains an access control issue which allows attackers to escalate privileges and execute arbitrary code via uploading a crafted PHP file to the virtual host directory...
How severe is CVE-2022-48079?
CVE-2022-48079 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2022-48079?
Check the references section above for vendor advisories and patch information. Affected products include: Mengnai Aapanel Host System.