Description
CloudPanel has an authentication bypass vulnerability. An attacker can bypass the authentication with a specially crafted HTTP request and get access to the file-manager.
Remediation
Upgrade to the latest version of CloudPanel
References
Related Vulnerabilities
WordPress Plugin PDF Embedder Security Bypass (4.4)
Plone CMS Permissions, Privileges, and Access Controls Vulnerability (CVE-2012-5498)
SugarCRM Improper Control of Generation of Code ('Code Injection') Vulnerability (CVE-2019-17303)
PHP NULL Pointer Dereference Vulnerability (CVE-2016-7131)
Internet Information Services Other Vulnerability (CVE-2002-0071)