CVE-2024-39907 is a critical SQL injection vulnerability affecting Fit2Cloud 1Panel, a web-based Linux server management control panel. Multiple SQL injection flaws, some with insufficient filtering, can lead to arbitrary file writes and ultimately remote code execution (RCE). With a CVSS score of 9.8 (CRITICAL) and an EPSS score indicating high exploitability, this vulnerability poses a significant risk due to its network-based attack vector, low attack complexity, and complete compromise potential. While not yet in CISA's KEV catalog, authenticated Nuclei templates exist, and users are strongly advised to upgrade to version 1.10.12-tls immediately as there are no known workarounds.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 1.10.9-lts, < 1.10.12-ltsCPE matchmatch criteria | cpe:2.3:a:fit2cloud:1panel:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.