Impact
The vulnerability is a command injection flaw (CWE-77) in the advanced/curl component of Osbil Technology oPanel v1.19.50 and earlier. The flaw allows an authenticated attacker to supply a malicious URL that is executed as a shell command, giving the attacker full control of the server’s operating system.
Affected Systems
This vulnerability affects Osbil Technology oPanel version 1.19.50 and any earlier releases, with the advanced/curl module processing the supplied ‘url’ parameter.
Risk and Exploitability
The CVSS score of 8.1 indicates a high level of risk. The EPSS score of 1% suggests a low to moderate probability of exploitation, though it is not listed in CISA’s KEV catalog. Once valid credentials are obtained, an attacker can execute arbitrary shell commands, making the impact potentially catastrophic. The likely attack vector is an authenticated web request to advanced/curl that manipulates the url parameter.
OpenCVE Enrichment