LiveActive security incident?Get immediate response
CVE Record

CVE-2021-47949: CyberPanel 2.1 Authenticated Remote Code Execution via Symlink Attack

CyberPanel 2.1 contains a command execution vulnerability that allows authenticated attackers to read arbitrary files and execute remote code by exploiting symlink attacks through the filemanager controller endpoint. Attackers can manipulate the completeStartingPath parameter in POST requests to /filemanager/controller to create symbolic links, read sensitive files like database credentials, and execute arbitrary shell commands through the /websites/fetchFolderDetails endpoint.

HighCVSS 8.8Not KEV-listedUpdated
Glexia's TakeAutomated analysishigh

Security readout for executives and security teams

Plain-English summary

CyberPanel, a web hosting control panel, has a flaw in version 2.1 and earlier that lets a logged-in user trick the system into reading sensitive files and running their own commands on the server. An attacker who already has a low-privilege account can take full control of the hosting environment, exposing customer data and websites.

Executive priority

Treat as a high-priority remediation for any organization running CyberPanel-managed hosting, especially multi-tenant environments. Customer data, site content, and downstream services on the same host are all at risk if a single account is abused or stolen.

Technical view

The file manager endpoint at /filemanager/controller fails to validate the completeStartingPath parameter, allowing an authenticated user to create symbolic links pointing to arbitrary filesystem locations. By chaining this with /websites/fetchFolderDetails, the attacker can read protected files (such as database credentials) and execute shell commands. The issue is tracked as CWE-59 (link following) with CVSS 8.8.

Likely exposure

Internet-exposed CyberPanel 2.1 and earlier instances where attackers can obtain or have already obtained any valid account, including reseller, customer, or compromised admin credentials. Shared hosting deployments are particularly exposed because multiple low-privilege tenants exist by design.

Exploitation context

A public proof-of-concept exists on ExploitDB (entry 50230) and VulnCheck has published a third-party advisory describing the attack chain. The CVE is not listed in CISA KEV at this time, so confirmed in-the-wild exploitation is not established in the cited sources, but working exploit code is publicly available.

Researcher notes

CWE-59 symlink handling on completeStartingPath is the root cause; the secondary read/execute path runs through fetchFolderDetails. Public PoC (EDB-50230) and VulnCheck's advisory describe the chain in enough detail to reproduce in a lab. Confirm fix availability against the upstream GitHub repository before deploying, as no patched version is named in the source bundle.

Mitigation direction

  • Upgrade CyberPanel beyond version 2.1 once a fixed release is confirmed by the vendor.
  • Restrict the CyberPanel admin interface to trusted IP ranges or a VPN.
  • Rotate any credentials, API keys, and database secrets stored on affected hosts.
  • Audit user accounts and disable unused or stale low-privilege accounts.
  • Place CyberPanel behind a WAF that can block unexpected /filemanager/controller payloads.
  • Monitor vendor channels (cyberpanel.net and the GitHub repository) for an official patch.

Validation and detection

  • Inventory all CyberPanel installations and record version numbers against the 2.1 cutoff.
  • Review web server and CyberPanel logs for POST requests to /filemanager/controller with unusual completeStartingPath values.
  • Check for unexpected symbolic links inside user home and document-root directories.
  • Inspect /websites/fetchFolderDetails access patterns for anomalous folder traversal.
  • Verify integrity of database credential files and rotate any that may have been exposed.
  • Run authenticated vulnerability scans against staging instances to confirm patched state once a fix is applied.
Prepared
Confidence
medium
Sources
6

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Potential ATT&CK relevance

Conservative CVE-to-ATT&CK context

These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.

ATT&CK lookup starting points

Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.

cwe · low confidence lookup

CWE-59: Exact CWE lookup

Use the exact CWE identifier as the starting point before reviewing related ATT&CK behavior. Open the exact CWE lookup page first, then review the ATT&CK searches from that MITRE weakness context. This is a Glexia lookup hint, not an official ATT&CK mapping.

Open ATT&CK lookup
description · low confidence lookup

Execution behavior lookup

The CVE wording references code or command execution, so execution technique review may help defensive triage. This is a Glexia inferred lookup path, not an official MITRE, ATT&CK, or CVE Program mapping.

Open ATT&CK lookup
description · low confidence lookup

Database behavior lookup

The CVE wording references database injection or access, so collection and exfiltration review may help. This is a Glexia inferred lookup path, not an official MITRE, ATT&CK, or CVE Program mapping.

Open ATT&CK lookup
cve · low confidence lookup

CVE-2021-47949 mapping review

Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.

Open ATT&CK lookup
Vulnerability profileCVE Program record
Severity
High
CVSS
8.8 (3.1)
Known Exploited
No
Published

Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Official CVE source material

CNA and ADP enrichment extracted from CVE v5

These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.

2CVSS vectors
3Timeline events
1ADP providers
5Source links

SSVC decision data

CISA-ADPCISA Coordinator
Timestamp
Version
2.0.3
Exploitation: pocAutomatable: noTechnical Impact: total

CVSS vector scores

2 official scores

We collect every scored CVSS vector available in the official CNA and ADP containers. When more than one version is present, the table keeps the source vectors side by side instead of collapsing them into the highest score.

ScoreVersionSeverityVectorExploitImpactSource
8.8CVSS 3.1HighCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H2.85.9VulnCheck
8.7CVSS 4.0HighCVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:NVulnCheck

Vulnerability scoring details

Base CVSS 4.0 score

8.7High
CVSS 4.0 vector shape for CVE-2021-47949Attack VectorAttack ComplexityAttack RequirementsPrivileges RequiredUser InteractionVS ConfidentialityVS IntegrityVS AvailabilitySS ConfidentialitySS IntegritySS Availability

Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

Attack Vector
NetworkAdjacentLocalPhysical
Attack Complexity
LowHigh
Attack Requirements
NonePresent
Privileges Required
NoneLowHigh
User Interaction
NonePassiveActive
VS Confidentiality
HighLowNone
VS Integrity
HighLowNone
VS Availability
HighLowNone
SS Confidentiality
HighLowNone
SS Integrity
HighLowNone
SS Availability
HighLowNone

Vulnerability timeline

Timeline events are normalized from CVE metadata, CNA source timelines, ADP timelines, and KEV metadata when present.

  1. CVE reservedCVE Program

    The CVE ID was reserved by the assigning CNA.

  2. CVE publishedCVE Program

    The CVE record was published.

  3. CVE updatedCVE Program

    The CVE record metadata indicates this as the latest update time.

ADP provider summaries

CISA-ADPCISA ADP Vulnrichment
other:ssvc

Source materials

Affected products

Products and packages named in the record

VendorProductVersion / packageStatus
CyberpanelCyberPanel<= 2.1Listed
Weakness

CWE details

CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.

CWE-59 · source CWE mapping

Improper Link Resolution Before File Access ('Link Following')

Improper Link Resolution Before File Access ('Link Following') represents a recurring weakness pattern that can create exploitable paths when design, validation, or implementation controls are missing.