Impact
CyberPanel versions before 2.4.4 attempt to determine whether a domain is an alias of another by using an ORM query filter rather than a Python 'if' statement. This incorrect logic can cause a legitimate domain to be misidentified as an alias. Consequently, an attacker who can submit domain information may create a domain that serves the same content as a primary domain without proper authorization. The flaw is mapped to CWE-1025.
Affected Systems
The affected product is CyberPanel; all releases older than version 2.4.4 are vulnerable. No sub‑version constraints are listed beyond the major revision point.
Risk and Exploitability
The CVSS score of 7.7 indicates high severity, while the EPSS score of < 1% suggests a low probability of exploitation. The vulnerability is not listed in the CISA KEV catalog. Based on the description, it is inferred that an attacker must be able to submit domain data through the application, which typically requires administrative privileges or sufficient rights to manage domains. Once such privileges are obtained, creating an unauthorized alias would be straightforward due to the incorrect ORM query; however, overall risk remains limited until the necessary privileges are in reach.
OpenCVE Enrichment