mirror of
https://github.com/cloudpanel-io/cloudpanel-ce.git
synced 2026-04-05 20:31:58 +02:00
hack create account #133
Reference in New Issue
Block a user
Delete Branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Originally created by @ystartgo on 1/25/2025
CloudPanel version(s) affected
v2.4.2
Description
My cloudpanel was hacked and I registered two management accounts.
I don’t know how I got in.
The original administrative account password is not the password but two-step verification is not enabled.
I didn’t see the reason for the incident, so I had to reinstall the entire system using Ubuntu 22.04 64 Bit.
How to reproduce
Unable to reproduce and find the vulnerability
Possible Solution
Block the following IPs
218.92.0.136
92.255.85.253
185.147.124.54
85.31.47.195
92.255.85.107
Additional Context
No response