CVE-2021-47949: CyberPanel 2.1 Authenticated Remote Code Execution via Symlink Attack
CyberPanel 2.1 contains a command execution vulnerability that allows authenticated attackers to read arbitrary files and execute remote code by exploiting symlink attacks through the filemanager controller endpoint. Attackers can manipulate the completeStartingPath parameter in POST requests to /filemanager/controller to create symbolic links, read sensitive files like database credentials, and execute arbitrary shell commands through the /websites/fetchFolderDetails endpoint.
Security readout for executives and security teams
Plain-English summary
CyberPanel, a web hosting control panel, has a flaw in version 2.1 and earlier that lets a logged-in user trick the system into reading sensitive files and running their own commands on the server. An attacker who already has a low-privilege account can take full control of the hosting environment, exposing customer data and websites.
Executive priority
Treat as a high-priority remediation for any organization running CyberPanel-managed hosting, especially multi-tenant environments. Customer data, site content, and downstream services on the same host are all at risk if a single account is abused or stolen.
Technical view
The file manager endpoint at /filemanager/controller fails to validate the completeStartingPath parameter, allowing an authenticated user to create symbolic links pointing to arbitrary filesystem locations. By chaining this with /websites/fetchFolderDetails, the attacker can read protected files (such as database credentials) and execute shell commands. The issue is tracked as CWE-59 (link following) with CVSS 8.8.
Likely exposure
Internet-exposed CyberPanel 2.1 and earlier instances where attackers can obtain or have already obtained any valid account, including reseller, customer, or compromised admin credentials. Shared hosting deployments are particularly exposed because multiple low-privilege tenants exist by design.
Exploitation context
A public proof-of-concept exists on ExploitDB (entry 50230) and VulnCheck has published a third-party advisory describing the attack chain. The CVE is not listed in CISA KEV at this time, so confirmed in-the-wild exploitation is not established in the cited sources, but working exploit code is publicly available.
Researcher notes
CWE-59 symlink handling on completeStartingPath is the root cause; the secondary read/execute path runs through fetchFolderDetails. Public PoC (EDB-50230) and VulnCheck's advisory describe the chain in enough detail to reproduce in a lab. Confirm fix availability against the upstream GitHub repository before deploying, as no patched version is named in the source bundle.
Mitigation direction
Upgrade CyberPanel beyond version 2.1 once a fixed release is confirmed by the vendor.
Restrict the CyberPanel admin interface to trusted IP ranges or a VPN.
Rotate any credentials, API keys, and database secrets stored on affected hosts.
Audit user accounts and disable unused or stale low-privilege accounts.
Place CyberPanel behind a WAF that can block unexpected /filemanager/controller payloads.
Monitor vendor channels (cyberpanel.net and the GitHub repository) for an official patch.
Validation and detection
Inventory all CyberPanel installations and record version numbers against the 2.1 cutoff.
Review web server and CyberPanel logs for POST requests to /filemanager/controller with unusual completeStartingPath values.
Check for unexpected symbolic links inside user home and document-root directories.
Inspect /websites/fetchFolderDetails access patterns for anomalous folder traversal.
Verify integrity of database credential files and rotate any that may have been exposed.
Run authenticated vulnerability scans against staging instances to confirm patched state once a fix is applied.
Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.
Potential ATT&CK relevance
Conservative CVE-to-ATT&CK context
These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.
ATT&CK lookup starting points
Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.
cwe · low confidence lookup
CWE-59: Exact CWE lookup
Use the exact CWE identifier as the starting point before reviewing related ATT&CK behavior. Open the exact CWE lookup page first, then review the ATT&CK searches from that MITRE weakness context. This is a Glexia lookup hint, not an official ATT&CK mapping.
The CVE wording references code or command execution, so execution technique review may help defensive triage. This is a Glexia inferred lookup path, not an official MITRE, ATT&CK, or CVE Program mapping.
The CVE wording references database injection or access, so collection and exfiltration review may help. This is a Glexia inferred lookup path, not an official MITRE, ATT&CK, or CVE Program mapping.
These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.
2CVSS vectors
3Timeline events
1ADP providers
5Source links
SSVC decision data
CISA-ADPCISA Coordinator
Timestamp
Version
2.0.3
Exploitation: pocAutomatable: noTechnical Impact: total
CVSS vector scores
2 official scores
We collect every scored CVSS vector available in the official CNA and ADP containers. When more than one version is present, the table keeps the source vectors side by side instead of collapsing them into the highest score.
CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.
CWE-59 · source CWE mapping
Improper Link Resolution Before File Access ('Link Following')
Improper Link Resolution Before File Access ('Link Following') represents a recurring weakness pattern that can create exploitable paths when design, validation, or implementation controls are missing.