CVE-2024-39911: FIT2CLOUD 1panel

Critical severity, CVSS 9.8. EPSS: 4.5% chance of exploitation in the next 30 days.

1Panel is a web-based linux server management control panel. 1Panel contains an unspecified sql injection via User-Agent handling. This issue has been addressed in version 1.10.12-lts. Users are advised to upgrade. There are no known workarounds for this vulnerability.

Affected products

  • FIT2CLOUD 1panel: from 1.10.10-lts, before 1.10.12-lts (fixed in 1.10.12-lts)

Published 2024-07-18. Last modified 2026-06-17.