Loading
1Panel is a web-based linux server management control panel. There are many sql injections in the project, and some of them are not well filtered, leading to arbitrary file writes, and ultimately leading to RCEs. These sql injections have been resolved in version 1.10.12-tls. Users are advised to upgrade. There are no known workarounds for these issues.
Use CWE-89, Fit2cloud vendor hub and 1panel product page to widen CVE-2024-39907 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2024-39911, CVE-2025-56413 and CVE-2025-54424 for nearby disclosures in the same product family.