CVE-2025-34410 (CNNVD-202512-1978)
中文标题:
1Panel 跨站请求伪造漏洞
英文标题:
1Panel CSRF in Change Username Functionality Allows Account Lockout
漏洞描述
中文描述:
1Panel是中国1Panel社区的一个开源的Linux服务器运维管理面板。 1Panel 1.10.33版本至2.0.15版本存在跨站请求伪造漏洞,该漏洞源于更改用户名功能未实施CSRF防护,可能导致账户锁定和拒绝服务。
英文描述:
1Panel versions 1.10.33 - 2.0.15 contain a cross-site request forgery (CSRF) vulnerability in the Change Username functionality available from the settings panel (/settings/panel). The endpoint does not implement CSRF protections such as anti-CSRF tokens or Origin/Referer validation. An attacker can craft a malicious webpage that submits a username-change request; when a victim visits the page while authenticated, the browser includes valid session cookies and the request succeeds. This allows an attacker to change the victim’s 1Panel username without consent. After the change, the victim is logged out and unable to log in with the previous username, resulting in account lockout and denial of service.
CWE类型:
标签:
受影响产品
| 厂商 | 产品 | 版本 | 版本范围 | 平台 | CPE |
|---|---|---|---|---|---|
| LXware | 1Panel | - | ≤ 2.0.15 | - |
cpe:2.3:a:lxware:1panel:*:*:*:*:*:*:*:*
|
| fit2cloud | 1panel | * | - | - |
cpe:2.3:a:fit2cloud:1panel:*:*:*:*:*:*:*:*
|
解决方案
中文解决方案:
英文解决方案:
临时解决方案:
CVSS评分详情
4.0 (cna)
HIGHCVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N
时间信息
利用信息
数据源详情
| 数据源 | 记录ID | 版本 | 提取时间 |
|---|---|---|---|
| CVE | cve_CVE-2025-34410 |
2025-12-11 03:30:11 | 2026-01-12 02:11:32 |
| NVD | nvd_CVE-2025-34410 |
2025-12-24 03:00:12 | 2026-01-12 02:27:39 |
| CNNVD | cnnvd_CNNVD-202512-1978 |
2026-01-11 06:15:03 | 2026-01-12 02:38:00 |
版本与语言
安全公告
变更历史
查看详细变更
- vulnerability_type: 未提取 -> 跨站请求伪造
- cnnvd_id: 未提取 -> CNNVD-202512-1978
- data_sources: ['cve', 'nvd'] -> ['cnnvd', 'cve', 'nvd']
查看详细变更
- affected_products_count: 1 -> 2
- data_sources: ['cve'] -> ['cve', 'nvd']