Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-5xpq-2vmc-5cqp | 1Panel contains a cross-site request forgery (CSRF) vulnerability in the panel name management functionality |
Tue, 23 Dec 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Fit2cloud
Fit2cloud 1panel |
|
| CPEs | cpe:2.3:a:fit2cloud:1panel:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Fit2cloud
Fit2cloud 1panel |
|
| Metrics |
cvssV3_1
|
Thu, 11 Dec 2025 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 11 Dec 2025 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
1panel
1panel 1panel |
|
| Vendors & Products |
1panel
1panel 1panel |
Wed, 10 Dec 2025 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | 1Panel versions 1.10.33 through 2.0.15 contain a cross-site request forgery (CSRF) vulnerability in the panel name management functionality. The affected endpoint does not implement CSRF defenses such as anti-CSRF tokens or Origin/Referer validation. An attacker can craft a malicious webpage that submits a panel-name change request; if a victim visits the page while authenticated, the browser includes valid session cookies and the request succeeds. This allows a remote attacker to change the victim’s panel name to an arbitrary value without consent. | |
| Title | 1Panel CSRF Panel Name Modification | |
| Weaknesses | CWE-352 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-03-05T12:04:21.600Z
Reserved: 2025-04-15T19:15:22.601Z
Link: CVE-2025-34430
Updated: 2025-12-11T17:07:40.643Z
Status : Analyzed
Published: 2025-12-10T19:16:13.867
Modified: 2025-12-23T15:11:16.500
Link: CVE-2025-34430
No data.
OpenCVE Enrichment
Updated: 2025-12-11T16:20:14Z
Github GHSA