HTTP: CyberPanel website.py submitWebsiteCreation Command Injection

This signature detects attempts to exploit a known vulnerability against CyberPanel. A successful attack can lead to command injection and arbitrary code execution.

Extended Description

CyberPanel before 2.3.8 allows remote authenticated users to execute arbitrary commands via shell metacharacters in the phpSelection field to the websites/submitWebsiteCreation URI.

References

CVE: CVE-2024-53376

Short Name
HTTP:CTS:CYBRPNL-WEB-PY-CMD-INJ
Severity
Major
Recommended
False
Recommended Action
Drop
Category
HTTP
Keywords
CVE-2024-53376 Command CyberPanel Injection submitWebsiteCreation website.py
Release Date
07/03/2025
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3822
False Positive
Unknown

Found a potential security threat?