
CyberPanel Flaws Chain Authentication Bypass and Stored XSS Into Remote Code Execution
A newly disclosed chain of pre-authentication remote code execution vulnerabilities in CyberPanel could enable unauthenticated attackers to compromise exposed servers. The attack, named ShadowPanel by Pentera researcher Nir Chako, combines weaknesses in the platform’s AI Scanner component with its built-in cron-job functionality to move from unauthenticated access to host-level command execution. CyberPanel is a web […]
The post CyberPanel Flaws Chain Authentication Bypass and Stored XSS Into Remote Code Execution appeared first on Cyber Security News.