CVE-2024-51378 is a pre-authentication remote code execution vulnerability in CyberPanel affecting versions through 2.3.6 and the unpatched 2.3.7 release. The flaw is present in the getresetstatus functionality implemented in dns/views.py and ftp/views.py. Requests to the affected reset-status endpoints can bypass the intended authentication control because the relevant security middleware only protects POST requests, while the vulnerable code path remains reachable in a way that avoids that protection. An attacker can then supply shell metacharacters through the statusfile parameter, leading to command injection and arbitrary command execution on the server.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
3 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos (2 hidden).
This repository contains a working exploit for CVE-2024-51378, a remote code execution vulnerability in CyberPanel versions up to 2.3.7. The main script, run.py, is a Python tool that takes a list of target IPs/domains and optionally a command to execute. It exploits the /ftp/getresetstatus and /dns/getresetstatus HTTP endpoints by sending a specially crafted JSON payload that injects shell commands via the 'statusfile' parameter. If no command is specified, the exploit deploys an SSH key to /root/.ssh/authorized_keys on the target, granting persistent root access. If a command is provided, it executes that command remotely. The exploit requires the httpx library and is run from the command line. The README provides context, mitigation advice, and usage instructions. No fake or detection-only code is present; this is a functional exploit script targeting a real vulnerability.
This repository contains a single Metasploit module (Ruby file) that exploits three unauthenticated remote code execution vulnerabilities in CyberPanel, a popular web hosting control panel. The module targets CVE-2024-51567, CVE-2024-51568, and CVE-2024-51378, each corresponding to different HTTP endpoints and injection vectors within CyberPanel. The exploit does not require authentication and can be used against any accessible, vulnerable CyberPanel instance (typically on port 8090 over HTTPS). The module is weaponized, supporting arbitrary command execution via Metasploit's payload system, and is suitable for both proof-of-concept and real-world exploitation. The code is well-structured, leveraging Metasploit's HttpClient and AutoCheck features, and includes logic for detection, exploitation, and payload delivery. The main endpoints targeted are '/dataBases/upgrademysqlstatus', '/filemanager/upload', '/ftp/getresetstatus', and '/dns/getresetstatus'. The module is intended for use by penetration testers and red teamers to demonstrate the impact of these vulnerabilities.
This repository contains a proof-of-concept exploit for CVE-2024-51378, a pre-authentication remote code execution vulnerability in CyberPanel versions 2.3.5, 2.3.6, and 2.3.7 (before patch) running on Linux. The exploit is implemented in a single Python script (CVE-2024-51378.py) and is accompanied by a detailed README. The exploit works by sending crafted OPTIONS HTTP requests to either the '/ftp/getresetstatus' or '/dns/getresetstatus' endpoints of a vulnerable CyberPanel instance. The script first retrieves a CSRF token from the target, then allows the user to interactively input arbitrary shell commands, which are injected via the 'statusfile' parameter in the request payload. Successful exploitation results in the execution of arbitrary commands on the target server as the web application user. The exploit requires only network access to the CyberPanel interface and does not require authentication. No hardcoded payload is present; the user supplies commands interactively. The repository is well-structured, with clear usage instructions and references to further information.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
8 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A pre-authentication remote code execution vulnerability in CyberPanel, referenced as a Metasploit module PR.
Unknown (described only as an incorrect default permissions issue; included in a CISA KEV-related list).
A remote code execution vulnerability in CyberPanel that allows attackers to execute arbitrary code on the server.
A vulnerability affecting CyberPanel, details unspecified but likely allows remote exploitation for initial access.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.