Metrics
Affected Vendors & Products
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-wrvc-x3wf-j5f5 | 1Panel contains a cross-site request forgery (CSRF) vulnerability in the web port configuration functionality |
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Thu, 11 Dec 2025 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 11 Dec 2025 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
1panel
1panel 1panel |
|
| Vendors & Products |
1panel
1panel 1panel |
Wed, 10 Dec 2025 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | 1Panel versions 1.10.33 - 2.0.15 contain a cross-site request forgery (CSRF) vulnerability in the web port configuration functionality. The port-change endpoint lacks CSRF defenses such as anti-CSRF tokens or Origin/Referer validation. An attacker can craft a malicious webpage that submits a port-change request; when a victim visits it while authenticated, the browser includes valid session cookies and the request succeeds. This allows an attacker to change the port on which the 1Panel web service listens, causing loss of access on the original port and resulting in service disruption or denial of service, and may unintentionally expose the service on an attacker-chosen port. | |
| Title | 1Panel CSRF Web Port Configuration Change | |
| Weaknesses | CWE-352 | |
| References |
| |
| Metrics |
cvssV4_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2025-12-11T18:54:17.767Z
Reserved: 2025-04-15T19:15:22.601Z
Link: CVE-2025-34429
Updated: 2025-12-11T16:07:32.816Z
Status : Received
Published: 2025-12-10T19:16:13.720
Modified: 2025-12-10T19:16:13.720
Link: CVE-2025-34429
No data.
OpenCVE Enrichment
Updated: 2025-12-11T16:20:12Z
Github GHSA