CVE-2025-66292 is an arbitrary file deletion vulnerability affecting DPanel, an open-source server management panel, in versions prior to 1.9.2. Authenticated users can exploit a path traversal flaw in the /api/common/attach/delete interface to delete arbitrary files on the server. The vulnerability stems from improper sanitization of user-supplied paths, allowing '..' characters to bypass checks and be passed directly to the os.Remove function. This vulnerability carries a CVSS score of 8.1 (HIGH), indicating a network-based attack with low privileges required and no user interaction, leading to high integrity and availability impacts. The lack of a chroot/jail enforcement allows for significant damage. Currently, there is no evidence of active exploitation, nor are there publicly available exploits in Metasploit, Nuclei, or ExploitDB. However, the vulnerability has garnered significant community attention with 10 mentions, suggesting awareness among security researchers.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.9.2CPE matchmatch criteria | cpe:2.3:a:dpanel:dpanel:*:*:*:*:*:go:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.