References https://nvd.nist.gov/vuln/detail/CVE-2024-39911 https://github.com/1Panel-dev/1Panel/security/advisories/GHSA-7m53-pwp6-v3f5 https://avd.aliyun.com/detail?id=AVD-2024-39911 https://blog.mo60.cn/index.php/archives/1Panel_SQLinjection2Rce.html https://cn-sec.com/archives/2989788.html https://cn-sec.com/archives/2981293.html https://stack.chaitin.com/vuldb/detail/b7c60531-28a9-46c9-97c0-0f6f27d4c786 https://linux.do/t/topic/155571 https://www.ctfiot.com/208339.html https://www.bilibili.com/video/BV1tt8ue6EmU/ https://qkl.seebug.org/vuldb/ssvid-99864 https://blog.fit2cloud.com/?p=01541924-7dc6-429d-bd14-faae00bc9f76
Related VulnerabilitiesPoCccm-detect: Clear-Com Core Configuration Manager Panel - DetectPoCctrlpanel-installer: CtrlPanel Installer ExposurePoCopcache-control-panel: Opcache control Panel - Unauthenticated AccessPoCcpanel-mailman-xss: cPanel Mailman - Cross-Site ScriptingPoCCVE-2026-41940: cPanel & WHM - Authentication Bypass via Session-File CRLF InjectionPoCcPanel & WHM 权限绕过漏洞(CVE-2026-41940)PoCCVE-2024-13055: Dyn Business Panel Plugin <= 1.0.0 - Cross-Site Scripting飞致云 1Panel 未授权 设计缺陷漏洞飞致云 1Panel 身份验证缺陷漏洞dpanel /api/common/user/login 默认口令漏洞dpanel /api/app/compose/get-from-uri 文件读取漏洞(CVE-2025-53363)