CVE-2025-66292

HIGH
中文标题:
(暂无数据)
英文标题:
DPanel has an arbitrary file deletion vulnerability in /api/common/attach/delete interface
CVSS分数: 8.1
发布时间: 2026-01-15 16:19:55
漏洞类型: (暂无数据)
状态: PUBLISHED
数据质量分数: 0.30
数据版本: v2
漏洞描述
中文描述:

(暂无数据)

英文描述:

DPanel is an open source server management panel written in Go. Prior to 1.9.2, DPanel has an arbitrary file deletion vulnerability in the /api/common/attach/delete interface. Authenticated users can delete arbitrary files on the server via path traversal. When a user logs into the administrative backend, this interface can be used to delete files. The vulnerability lies in the Delete function within the app/common/http/controller/attach.go file. The path parameter submitted by the user is directly passed to storage.Local{}.GetSaveRealPath and subsequently to os.Remove without proper sanitization or checking for path traversal characters (../). And the helper function in common/service/storage/local.go uses filepath.Join, which resolves ../ but does not enforce a chroot/jail. This vulnerability is fixed in 1.9.2.

CWE类型:
CWE-22 CWE-73
标签:
(暂无数据)
受影响产品
厂商 产品 版本 版本范围 平台 CPE
donknap dpanel < 1.9.2 - - cpe:2.3:a:donknap:dpanel:<_1.9.2:*:*:*:*:*:*:*
解决方案
中文解决方案:
(暂无数据)
英文解决方案:
(暂无数据)
临时解决方案:
(暂无数据)
参考链接
https://github.com/donknap/dpanel/security/advisories/GHSA-vh2x-fw87-4fxq x_refsource_CONFIRM
cve.org
访问
https://github.com/donknap/dpanel/commit/cbda0d90204e8212f2010774345c952e42069119 x_refsource_MISC
cve.org
访问
https://github.com/donknap/dpanel/releases/tag/v1.9.2 x_refsource_MISC
cve.org
访问
CVSS评分详情
3.1 (cna)
HIGH
8.1
CVSS向量: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H
机密性
NONE
完整性
HIGH
可用性
HIGH
时间信息
发布时间:
2026-01-15 16:19:55
修改时间:
2026-01-15 16:44:51
创建时间:
2026-01-16 02:44:20
更新时间:
2026-01-16 02:48:08
利用信息
暂无可利用代码信息
数据源详情
数据源 记录ID 版本 提取时间
CVE cve_CVE-2025-66292 2026-01-16 02:18:19 2026-01-16 02:44:20
NVD nvd_CVE-2025-66292 2026-01-16 02:47:33 2026-01-16 02:48:08
版本与语言
当前版本: v2
主要语言: EN
支持语言:
EN
安全公告
暂无安全公告信息
变更历史
v2 NVD
2026-01-16 02:48:08
data_sources: ['cve'] → ['cve', 'nvd']
查看详细变更
  • data_sources: ['cve'] -> ['cve', 'nvd']