
🚨 High - CyberPanel Command Execution via Symlink (CVE-2021-47949) A vulnerability in CyberPanel 2.1 allows authenticated attackers to execute remote code and read arbitrary files. By manipulating the completeStartingPath parameter in the file manager controller, an attacker can perform a symlink attack to access sensitive data (like database credentials) and execute shell commands through the fetch folder endpoint. 👉 Affected: CyberPanel 2.1 | Upgrade to 2.1.2 version
Post summary
CVE-2021-47949 enables authenticated attackers to perform remote code execution in CyberPanel through a symlink attack, and the advisory recommends upgrading to version 2.1.2 to patch the issue.

