{"id":"CVE-2024-39907","aliases":["GHSA-5grx-v727-qmq6","GO-2024-2990"],"url":"https://o3.security/vulnerability/CVE-2024-39907","summary":"a sqlinjection in 1Panel ","details":"### Summary\nThere are many sql injections in the project, and some of them are not well filtered, leading to arbitrary file writes, and ultimately leading to RCEs.\nThe proof is as follows\n\n### Details （one of them ）\n<img width=\"697\" alt=\"image\" src=\"https://github.com/1Panel-dev/1Panel/assets/129351704/895b7b43-9bc0-44b3-9c84-24c2dcc962da\">\n<img width=\"936\" alt=\"image\" src=\"https://github.com/1Panel-dev/1Panel/assets/129351704/1b8eb866-9865-4bef-a359-53335d709157\">\n<img width=\"684\" alt=\"image\" src=\"https://github.com/1Panel-dev/1Panel/assets/129351704/e865d6d0-7ecb-49f7-b4a2-f1b0bc407986\">\n\n\n### PoC\ncurl 'http://api:30455/api/v1/hosts/command/search' {\"page\":1,\"pageSize\":10,\"groupID\":0,\"orderBy\":\"**3**\",\"order\":\"ascending\",\"name\":\"a\"}\n<img width=\"664\" alt=\"image\" src=\"https://github.com/1Panel-dev/1Panel/assets/129351704/250d5a2a-cb32-44dc-9831-86dbc2f2b43f\">\nfor example as picture . just change orderby‘s num we can know How many columns does the data table have.Parameters require strict whitelist filtering\n\n### Impact\nRCE、data leak.\n","published":"2024-07-18T15:31:30.892Z","modified":"2026-08-12T03:51:42.941522940Z","cvss":{"score":9.8,"severity":"CRITICAL","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"},"epss":null,"cisaKev":null,"exploitsKnown":1,"affectedPackages":[{"ecosystem":"Go","name":"github.com/1Panel-dev/1Panel","fixedVersion":"1.10.12-tls"}],"fix":{"url":"https://github.com/1Panel-dev/1Panel/commit/ff549a47937c1314e6ee08453a1d2128242440cd","label":"1Panel-dev/1Panel@ff549a4"},"references":[{"type":"ADVISORY","url":"https://github.com/1Panel-dev/1Panel/security/advisories/GHSA-5grx-v727-qmq6"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/39xxx/CVE-2024-39907.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-39907"},{"type":"WEB","url":"https://github.com/1Panel-dev/1Panel/commit/ff549a47937c1314e6ee08453a1d2128242440cd"},{"type":"PACKAGE","url":"https://github.com/1Panel-dev/1Panel"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T03:51:42.941522940Z"}}