Impact
This vulnerability exists in CyberPanel 2.4.3, where the file manager lacks validation of symbolic links within uploaded ZIP archives. An authenticated attacker who can upload files can craft a ZIP bundle that contains symlinks pointing outside the user’s home directory. When the archive is extracted, those links are created on disk and can subsequently be explored via the web interface, enabling the attacker to read arbitrary, potentially sensitive files on the server. The primary impact is information disclosure; the attacker can view system configuration files, credentials, or other confidential data that would otherwise be inaccessible to the authenticated user.
Affected Systems
Affected vendors and products include usmannasir:cyberpanel, specifically the CyberPanel version 2.4.3 deployment. The arbitrary file read flaw was addressed in the commit eca0c3c. No other version numbers are explicitly cited in the advisory, so only the 2.4.3 release is confirmed to be vulnerable until a newer patch is released.
Risk and Exploitability
The CVSS score is 7.1, indicating a high severity. EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalogue. The flaw requires an attacker to be authenticated to the file manager, so the attack vector is likely internal or based on compromised credentials. As the vulnerability permits only reading of files, it does not enable code execution or direct denial of service. However, the exposure of system files could be leveraged in a broader attack chain that might compromise additional services. The impact remains significant due to the potential leakage of credentials or configuration details.
OpenCVE Enrichment