VendorsMGT-COMMERCEcloudpanelall versions
Vulnerabilities

MGT-COMMERCE CloudPanel

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

6CVEs
CVE-2023-35885
CloudPanel 2 before 2.3.1 has insecure file-manager cookie authentication.
Published 2023-06-20 · Modified
9.8EPSS 0.749
CVE-2024-24320
Directory Traversal vulnerability in Mgt-commerce CloudPanel v.2.0.0 thru v.2.4.0 allows a remote attacker to obtain sensitive information and execute arbitrary code via the service parameter of the load-logfiles function.
Published 2024-06-14 · Modified
8.8EPSS 0.040
CVE-2023-46157
File-Manager in MGT CloudPanel 2.0.0 through 2.3.2 allows the lowest privilege user to achieve OS command injection by changing file ownership and changing file permissions to 4755.
Published 2023-12-08 · Modified
8.8EPSS 0.023
CVE-2023-36630
In CloudPanel before 2.3.1, insecure file upload leads to privilege escalation and authentication bypass.
Published 2023-06-25 · Modified
8.8EPSS 0.009
CVE-2023-0391
MGT-COMMERCE CloudPanel Shared Certificate
Published 2023-03-21 · Modified
8.1EPSS 0.006
CVE-2023-33747
CloudPanel v2.2.2 allows attackers to execute a path traversal.
Published 2023-06-06 · Modified
7.8EPSS 0.005