漏洞描述
CtrlPanel versions <= 1.1.1 are vulnerable to unauthenticated Remote Code Execution (RCE) via the web installer endpoint (public/installer/index.php). The installer loaded and executed form handler files before checking for the install.lock gate, allowing attackers to reach installer forms on fully-deployed instances. User-supplied POST values (url, key, clientkey) from the Pterodactyl configuration form were interpolated directly into shell command strings executed via bash -c without sanitization, enabling command injection. The vulnerability is confirmed actively exploited in the wild.
影响产品
暂无结构化产品信息。
修复建议
建议关注厂商安全公告,及时升级至已修复版本,并结合实际资产暴露情况采取缓解措施。