CVE-2023-35885 is a critical vulnerability in CloudPanel 2 (versions 2.0.0 up to, but not including, 2.3.1) due to insecure authentication in the file-manager component. The vulnerability arises from reliance on cookies for authentication without proper validation and integrity checking (CWE-565). This allows attackers to forge or manipulate authentication cookies, bypassing authentication controls and gaining unauthorized access to the file-manager functionality.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
2 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos.
This repository is an operational exploit for CVE-2023-35885, targeting CloudPanel 2 (prior to v2.3.1) via an insecure file-manager cookie authentication vulnerability. The exploit is implemented in Python (exploit.py) and uses a helper PHP script (Crypto.php) to generate the required authentication cookie. The main attack flow is: 1. The attacker generates a valid 'clp-fm' cookie using Crypto.php. 2. The exploit accesses the vulnerable /file-manager/ endpoint on the target, using the forged cookie. 3. It uploads a PHP web shell (shell.php) to /htdocs/app/files/public/ via the file-manager's backend endpoints. 4. The attacker then interacts with the shell via HTTP requests to /shell.php?cmd=COMMAND, achieving remote code execution as root. 5. The exploit supports both single-target and multi-target (file-based) modes, with optional output and threading. The repository contains a large number of PHP files, but the exploit is self-contained in exploit.py, Crypto.php, and shell.php. The rest of the files appear to be unrelated to the exploit and are likely part of a bundled copy of the CloudPanel source code for reference or analysis. The exploit is not part of a framework and is fully operational, providing an interactive shell to the attacker if successful.
This repository contains a working exploit for CVE-2023-35885, a critical vulnerability in CloudPanel versions 2.0.0 to 2.3.0. The exploit consists of a Python script ('exploit2.py') that leverages a flaw in the handling of the 'clp-fm' cookie, allowing an attacker to upload a PHP webshell ('shell.php') to the target server via the file manager endpoints. The script then uses the webshell to create a new user ('zeroday') with sudo privileges and a known password, effectively granting full system access to the attacker. The repository also includes a helper PHP script ('Crypto.php') to generate the required encrypted cookie. The attack is performed over HTTPS and targets specific endpoints in the CloudPanel file manager. The exploit is operational and weaponized, providing both remote code execution and privilege escalation. The codebase is primarily in Python and PHP, with clear entry points and a well-documented attack chain.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
No public activity tracked yet. Mallory keeps watching.
No public activity observed for this vulnerability.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.